MEDIUM
Simditor through 2.3.21 allows DOM XSS via an onload attribute within a malformed SVG element
Published May 13, 2019
6.1
MEDIUMCVSS 3.0
EPSS 1.54%
Description
Simditor through 2.3.21 allows DOM XSS via an onload attribute within a malformed SVG element.
Affected products
No data.
- ≤ 2.3.21
No data.
No Red Hat product state for this CVE.
simditor
npm
Introduced 0 Fixed 2.3.22
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | simditor | 0 | 2.3.22 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://github.com/advisories/GHSA-8v67-x8q5-3x3g Advisory
- https://github.com/hkglue/simditor_demo.git x_refsource_MISCExploitThird Party Advisory
- https://github.com/hkglue/simditor_dom_xss/blob/master/README.md x_refsource_MISCExploitThird Party Advisory
- https://github.com/mycolorway/simditor/commit/ef01a643cbb7f8163535d6bfb71135f80ec6a6fd x_refsource_MISCPatchThird Party Advisory
- https://github.com/mycolorway/simditor/releases/tag/v2.3.22 x_refsource_MISCRelease NotesThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-19048
- https://snyk.io/vuln/SNYK-JS-SIMDITOR-174638
- https://www.npmjs.com/advisories/884
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-8v67-x8q5-3x3g | Advisory | |
| https://github.com/hkglue/simditor_demo.git | x_refsource_MISCExploitThird Party Advisory | |
| https://github.com/hkglue/simditor_dom_xss/blob/master/README.md | x_refsource_MISCExploitThird Party Advisory | |
| https://github.com/mycolorway/simditor/commit/ef01a643cbb7f8163535d6bfb71135f80ec6a6fd | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/mycolorway/simditor/releases/tag/v2.3.22 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-19048 | ||
| https://snyk.io/vuln/SNYK-JS-SIMDITOR-174638 | ||
| https://www.npmjs.com/advisories/884 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 13, 2019
Updated Aug 5, 2024
Reserved Nov 6, 2018
Link CVE-2018-19048
CISA Vulnrichment
GHSA-8V67-X8Q5-3X3G Updated n/a