VDB
Sign up
MEDIUM6.1

GHSA-w974-rq9x-mh3v

Pandao Editor.md vulnerable to cross-site scripting (XSS) in iframe src parameter

Details

Cross-site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script in the `<iframe> src` parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/editor.md
Introduced in: 0

No fixed version published yet for editor.md (npm). Pin to a known-safe version or switch to an alternative.

References