xdan / jodit

Jodit - Best WYSIWYG Editor for You
https://xdsoft.net/jodit/
MIT License
1.71k stars 354 forks source link

CVE-2023-42399 #1017

Open Rays-l opened 1 year ago

Rays-l commented 1 year ago

CVE ID: CVE-2023-42399

PRODUCT: JoditEditor < v.4.0.0-beta.86

DETAILS: Jodit Editor v.4.0.0 beta.86 has an XSS vulnerability where the rich text editor does not completely filter out malicious XSS attack statements. Using payload: