Description
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
Remediation
References
https://github.com/pandao/editor.md/issues/715
Related Vulnerabilities
CVE-2023-40348 Vulnerability in maven package org.jenkins-ci.plugins:gogs-webhook
CVE-2022-26477 Vulnerability in maven package org.apache.systemds:systemds
CVE-2017-18640 Vulnerability in maven package org.yaml:snakeyaml
CVE-2021-23648 Vulnerability in npm package @braintree/sanitize-url
CVE-2022-4375 Vulnerability in maven package net.mingsoft:ms-mcms