MEDIUM6.1
GHSA-5p84-mmh9-pxgr
Pandao Editor.md vulnerable to cross-site scripting (XSS) in editor parameter
Details
Cross-site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the `editor` parameter.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/editor.md
Introduced in:
0No fixed version published yet for editor.md (npm). Pin to a known-safe version or switch to an alternative.