Headline
GHSA-m5jf-8crm-r65m: Vditor allows Cross-site Scripting via an attribute of an `A` element
Vditor 3.10.3 allows XSS via an attribute of an A
element.
NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true
.
Vditor allows Cross-site Scripting via an attribute of an `A` element
Moderate severity GitHub Reviewed Published May 3, 2024 to the GitHub Advisory Database • Updated May 3, 2024