CVE-2022-23461
MEDIUM6.1EPSS 0.11%Jodit Editor vulnerable to Cross-site Scripting
發布日:2022/9/25修改日:2023/11/8
描述
Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vulnerable to XSS attacks when pasting specially constructed input. This issue has not been fully patched. There are no known workarounds.
受影響套件(1)
- npm/joditfrom 0, <= 3.24.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |