CVE-2023-29641

MEDIUM6.1EPSS 0.50%

editor.md vulnerable to Cross-site Scripting

Published: 5/1/2023Modified: 11/8/2023

Description

Cross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script or HTML via crafted markdown text.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (3)