Description
A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown function of the component Pug to PDF Converter. The manipulation leads to cross site scripting. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.2.5
References
Related Issues
- TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements - CVE-2024-38357
- Cross-site scripting vulnerability in TinyMCE plugins - CVE-2024-21910
- Cross-site scripting vulnerability in TinyMCE - CVE-2024-21908
- Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerability - CVE-2024-43407
You might also like:
- Tags:
- npm
- relaxedjs
Anything's wrong? Let us know Last updated on October 08, 2024


