QID 980802
QID 980802: Nodejs (npm) Security Update for editor.md (GHSA-x3g3-334f-q6h4)
pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-x3g3-334f-q6h4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-x3g3-334f-q6h4 -
github.com/advisories/GHSA-x3g3-334f-q6h4
CVEs related to QID 980802
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x3g3-334f-q6h4 | editor.md |
|