Description
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
Remediation
References
https://github.com/pandao/editor.md/issues/715
Related Vulnerabilities
CVE-2022-29546 Vulnerability in maven package net.sourceforge.htmlunit:neko-htmlunit
CVE-2021-43466 Vulnerability in maven package org.thymeleaf:thymeleaf-spring5
CVE-2023-31544 Vulnerability in maven package org.opencms:opencms-core
CVE-2011-2481 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2020-36188 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind