Description
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
Remediation
References
https://github.com/pandao/editor.md/issues/715
Related Vulnerabilities
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http_2.13
CVE-2020-7601 Vulnerability in npm package gulp-scss-lint
CVE-2021-25916 Vulnerability in npm package patchmerge
CVE-2022-0272 Vulnerability in maven package io.gitlab.arturbosch.detekt:detekt-core
CVE-2022-32065 Vulnerability in maven package com.ruoyi:ruoyi