Vditor 3.10.3 allows XSS via an attribute of an A
element.
NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true
.
{ "nvd_published_at": "2024-05-03T16:15:11Z", "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-05-03T20:38:15Z" }