Jodit Editor vulnerable to Cross-site Scripting
Moderate severity
GitHub Reviewed
Published
Sep 25, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Sep 24, 2022
Published to the GitHub Advisory Database
Sep 25, 2022
Reviewed
Sep 27, 2022
Last updated
Jan 28, 2023
Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vulnerable to XSS attacks when pasting specially constructed input. This issue has not been fully patched. There are no known workarounds.
References