Description
pandao Editor.md 1.5.0 allows XSS via the Javascript: string.
Remediation
References
https://github.com/pandao/editor.md/issues/709
Related Vulnerabilities
CVE-2020-11023 Vulnerability in maven package org.webjars.bower:jquery
CVE-2021-21141 Vulnerability in maven package org.webjars.npm:electron
CVE-2019-18212 Vulnerability in maven package org.lsp4xml:lsp4xml-extensions
CVE-2022-41929 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore