VDB
Sign up
MEDIUM

GHSA-m5jf-8crm-r65m

Vditor allows Cross-site Scripting via an attribute of an `A` element

Details

Vditor 3.10.3 allows XSS via an attribute of an `A` element.

NOTE: the vendor indicates that a user is supposed to mitigate this via `sanitize=true`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/vditor

No fixed version published yet for vditor (npm). Pin to a known-safe version or switch to an alternative.

References