Vulnerabilities/

Cross-Site Scripting in simditor

Severity:
Medium

Description

Versions of simditor prior to 2.3.22 are vulnerable to Cross-Site Scripting. The package does not sanitize user input that is rendered with innerHTML, allowing attackers to execute arbitrary JavaScript.

Recommendation

Update the simditor package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
simditor
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing