MEDIUM6.1
GHSA-4wh3-3wf2-39m9
Summernote vulnerable to cross-site scripting
Details
Cross Site Scripting vulnerability in Summernote v.0.8.18 and before allows a remote attacker to execute arbtirary code via a crafted payload to the `codeview` parameter.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/summernote
Introduced in:
0No fixed version published yet for summernote (npm). Pin to a known-safe version or switch to an alternative.