CVE-2024-34449

EPSS 0.19%

Vditor allows Cross-site Scripting via an attribute of an `A` element

Published: 5/3/2024Modified: 5/3/2024
Also known as:GHSA-m5jf-8crm-r65m

Description

Vditor 3.10.3 allows XSS via an attribute of an `A` element. NOTE: the vendor indicates that a user is supposed to mitigate this via `sanitize=true`.

Affected packages (1)

References (4)