3.10.8
5 years ago
13 days ago
Known vulnerabilities in the vditor package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
vditor is a ♏ 易于使用的 Markdown 编辑器,为适配不同的应用场景而生 Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to an improper sanitization. How to fix Cross-site Scripting (XSS)? Upgrade | <3.8.13 |
vditor is a ♏ 易于使用的 Markdown 编辑器,为适配不同的应用场景而生 Affected versions of this package are vulnerable to Cross-site Scripting (XSS) when a user creates a link using the markdown syntax, the server does not URL-encode the double-quotes, so the user can escape the href attribute. How to fix Cross-site Scripting (XSS)? Upgrade | <3.8.13 |