MEDIUM 6.1 npm
Jodit Editor vulnerable to Cross-site Scripting
GHSA-42hx-vrxx-5r6v · CVE-2022-23461
Published · Modified
Description
Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vulnerable to XSS attacks when pasting specially constructed input. This issue has not been fully patched. There are no known workarounds.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes