vditor是一款浏览器端的 Markdown 编辑器,支持所见即所得、即时渲染(类似 Typora)和分屏预览模式。 vditor 3.8.13 之前版本存在跨站脚本漏洞,该漏洞源于用户如果在使用 markdown 语法创建链接时作为 URL 值传递,则没有清理过程,链接将按原样创建。攻击者通过此漏洞能够执行恶意脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vanessa219 | vanessa219/vditor | unspecified ~ 3.8.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet