Versions of simditor prior to 2.3.22 are vulnerable to Cross-Site Scripting. The package does not sanitize user input that is rendered with innerHTML, allowing attackers to execute arbitrary JavaScript.
Upgrade to version 2.3.22 or later.
{
"severity": "MODERATE",
"cwe_ids": [
"CWE-79"
],
"nvd_published_at": null,
"github_reviewed_at": "2019-05-14T01:08:11Z",
"github_reviewed": true
}