CVE-2022-23461

Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vulnerable to XSS attacks when pasting specially constructed input. This issue has not been fully patched. There are no known workarounds.
References
Link Resource
https://securitylab.github.com/advisories/GHSL-2022-030_xdan_jodit/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:xdsoft:jodit_editor:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-09-24 03:15

Updated : 2024-02-28 19:29


NVD link : CVE-2022-23461

Mitre link : CVE-2022-23461

CVE.ORG link : CVE-2022-23461


JSON object : View

Products Affected

xdsoft

  • jodit_editor
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')