Description
A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown function of the component Pug to PDF Converter. The manipulation leads to cross site scripting. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.2.5
References
Could your website be exposed too?
SmartScanner can check your website for ReLaXed Cross-site Scripting vulnerability and gives you actionable findings to investigate.
Start a free scanRelated Issues
- TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements - CVE-2024-38357
- Cross-site scripting vulnerability in TinyMCE plugins - CVE-2024-21910
- Cross-site scripting vulnerability in TinyMCE - CVE-2024-21908
- Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerability - CVE-2024-43407


