MEDIUM6.1
GHSA-wv83-jrfh-rp33
Cross site scripting in kindeditor
Details
Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this editor (the file suffix is allowed).
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/kindeditor
Introduced in:
0No fixed version published yet for kindeditor (npm). Pin to a known-safe version or switch to an alternative.