Description
Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this editor (the file suffix is allowed).
Recommendation
No fix is available yet. Followings are affected versions:
- <= 4.1.12
References
Related Issues
- Cross-site Scripting in epubjs - CVE-2021-33040
- Cross-site Scripting in bootstrap-table - bootstrap-table - CVE-2021-23472
- Cross-site Scripting in sanitize-url - CVE-2021-23648
- Cross site scripting in datatables.net - CVE-2021-23445
You might also like:
- Tags:
- npm
- kindeditor
Anything's wrong? Let us know Last updated on February 01, 2023


