Versions of simditor
prior to 2.3.22 are vulnerable to Cross-Site Scripting. The package does not sanitize user input that is rendered with innerHTML
, allowing attackers to execute arbitrary JavaScript.
Upgrade to version 2.3.22 or later.
{ "nvd_published_at": null, "github_reviewed_at": "2019-05-14T01:08:11Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-79" ] }