QID 980809
QID 980809: Nodejs (npm) Security Update for simplemde (GHSA-wg85-p6j7-gp3w)
SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters, which is mishandled during construction of an A element.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-wg85-p6j7-gp3w for updates pertaining to this vulnerability.
Vendor References
- GHSA-wg85-p6j7-gp3w -
github.com/advisories/GHSA-wg85-p6j7-gp3w
CVEs related to QID 980809
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wg85-p6j7-gp3w | simplemde |
|