Vulnerabilities/

Summernote vulnerable to cross-site scripting

Severity:
Medium

Description

Cross Site Scripting vulnerability in Summernote v.0.8.18 and before allows a remote attacker to execute arbtirary code via a crafted payload to the codeview parameter.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
summernote
Anything's wrong? Let us know Last updated on April 12, 2024

This issue is available in SmartScanner Professional

See Pricing