VDB
Sign up
MEDIUM6.1

GHSA-wv83-jrfh-rp33

Cross site scripting in kindeditor

Details

Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this editor (the file suffix is allowed).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/kindeditor
Introduced in: 0

No fixed version published yet for kindeditor (npm). Pin to a known-safe version or switch to an alternative.

References