Vulnerabilities/

Cross-Site Scripting in editor.md

Severity:
Medium

Description

All versions of editor.md are vulnerable to Cross-Site Scripting. User input is insufficiently sanitized, allowing attackers to inject malicious code in payloads containing base64-encoded content.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
editor.md
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing