sparksuite / simplemde-markdown-editor

A simple, beautiful, and embeddable JavaScript Markdown editor. Delightful editing for beginners and experts alike. Features built-in autosaving and spell checking.
https://simplemde.com
MIT License
9.79k stars 1.12k forks source link

🚨 Potential Cross-site Scripting (XSS) - Stored (CWE-79) #816

Open huntr-helper opened 3 years ago

huntr-helper commented 3 years ago

👋 Hello, @WesCossick, @adam187, @frm - a potential medium severity Cross-site Scripting (XSS) - Stored (CWE-79) vulnerability in your repository has been disclosed to us.

Next Steps

1️⃣ Visit https://huntr.dev/bounties/1-other-sparksuite/simplemde-markdown-editor for more advisory information.

2️⃣ Sign-up to validate or speak to the researcher for more assistance.

3️⃣ Propose a patch or outsource it to our community - whoever fixes it gets paid.


Confused or need more help?


This issue was automatically generated by huntr.dev - a bug bounty board for securing open source code.