textAngular Cross-site Scripting vulnerability
Moderate severity
GitHub Reviewed
Published
Feb 21, 2023
to the GitHub Advisory Database
•
Updated Feb 22, 2023
Description
Published by the National Vulnerability Database
Feb 21, 2023
Published to the GitHub Advisory Database
Feb 21, 2023
Reviewed
Feb 22, 2023
Last updated
Feb 22, 2023
textAngular is a text editor for Angular.js. Version 1.5.16 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. There are no known patches.
References