Description
Stored XSS was discovered in the tree mode of jsoneditor before 9.0.2 through injecting and executing JavaScript.
Recommendation
Update the jsoneditor package to the latest compatible version. Followings are version details:
- Affected version(s): < 9.0.2
- Patched version(s): 9.0.2
References
Related Issues
- Cross-site Scripting in Joplin - CVE-2020-15930
- Cross-site Scripting in dompurify (GHSA-63q7-h895-m982) - CVE-2020-26870
- Cross-site Scripting in vis-timeline - CVE-2020-28487
- Cross-site Scripting (XSS) in Eclipse Theia - CVE-2020-27224
- Tags:
- npm
- jsoneditor
Anything's wrong? Let us know Last updated on February 01, 2023