MEDIUM5.4
GHSA-pq37-4c4g-v38c
Cross-site Scripting in vditor
Quick fix
GHSA-pq37-4c4g-v38c — vditor: upgrade to the fixed version with the command below.
npm install vditor@3.8.11Details
vditor prior to version 3.8.11 is vulnerable to cross-site scripting.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-0341[ADVISORY]
- https://github.com/Vanessa219/vditor/issues/1102[WEB]
- https://github.com/vanessa219/vditor/commit/219f8a9e272aba3cbc0096a82cac776532dbb9e5[WEB]
- https://github.com/vanessa219/vditor[PACKAGE]
- https://huntr.dev/bounties/fa546b57-bc15-4705-824e-9474b616f628[WEB]