VDB
Sign up
MEDIUM6.1

GHSA-p9wj-wrrm-84m5

Simditor XSS Vulnerability

Details

Simditor v2.3.11 allows XSS via crafted use of `svg/onload=alert` in a TEXTAREA element, as demonstrated by Firefox 54.0.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/simditor
Introduced in: 0

No fixed version published yet for simditor (npm). Pin to a known-safe version or switch to an alternative.

References