Vulnerabilities/

Vditor allows Cross-site Scripting via an attribute of an `A` element

Severity:
Medium

Description

Vditor 3.10.3 allows XSS via an attribute of an A element.

NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
vditor
Anything's wrong? Let us know Last updated on May 03, 2024

This issue is available in SmartScanner Professional

See Pricing