logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-23474

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-23474

Description:
Editor.js is a block-style editor with clean JSON output. Versions prior to 2.26.0 are vulnerable to Code Injection via pasted input. The processHTML method passes pasted input into wrapper’s innerHTML. This issue is patched in version 2.26.0.
Last updated date:
12/20/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
12/20/2022
Reference url to background

https://github.com/codex-team/editor.js/pull/2100

Type:
exploit
Confidence:
HIGH
Date of publishing:
12/20/2022
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy