VDB
Sign up
MEDIUM6.1

GHSA-4wh3-3wf2-39m9

Summernote vulnerable to cross-site scripting

Details

Cross Site Scripting vulnerability in Summernote v.0.8.18 and before allows a remote attacker to execute arbtirary code via a crafted payload to the `codeview` parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/summernote
Introduced in: 0

No fixed version published yet for summernote (npm). Pin to a known-safe version or switch to an alternative.

References