MEDIUM6.1
GHSA-p9wj-wrrm-84m5
Simditor XSS Vulnerability
Details
Simditor v2.3.11 allows XSS via crafted use of `svg/onload=alert` in a TEXTAREA element, as demonstrated by Firefox 54.0.1.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/simditor
Introduced in:
0No fixed version published yet for simditor (npm). Pin to a known-safe version or switch to an alternative.