ZeroHour

CVE-2022-23461

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p45
Published
()
Modified
Description

Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vulnerable to XSS attacks when pasting specially constructed input. This issue has not been fully patched. There are no known workarounds.

Vendors
xdsoft
Products
jodit editor
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.