Description
Versions of simditor prior to 2.3.22 are vulnerable to Cross-Site Scripting. The package does not sanitize user input that is rendered with innerHTML, allowing attackers to execute arbitrary JavaScript.
Recommendation
Update the simditor package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.3.22
- Patched version(s): 2.3.22
References
Related Issues
- Joplin Vulnerable to Cross-site Scripting in Note Content - CVE-2018-1000534
- Bootstrap Cross-site Scripting vulnerability - bootstrap - GHSA-pj7m-g53m-7638 - CVE-2018-14041
- Json2html vulnerable to cross-site scripting - CVE-2018-25053
- Bootstrap vulnerable to Cross-Site Scripting (XSS) - CVE-2018-14040
You might also like:
- Tags:
- npm
- simditor
Anything's wrong? Let us know Last updated on January 09, 2023


