CVE-2024-34449
EPSS 0.19%Vditor allows Cross-site Scripting via an attribute of an `A` element
發布日:2024/5/3修改日:2024/5/3
描述
Vditor 3.10.3 allows XSS via an attribute of an `A` element. NOTE: the vendor indicates that a user is supposed to mitigate this via `sanitize=true`.