OSV 1.4.0 · github-reviewed · 修改于 2021-09-24 02:55
发布时间
2020-08-12 03:40
GitHub 审查时间
2020-08-12 03:39
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/08/GHSA-j7wp-vjj6-cp5m/GHSA-j7wp-vjj6-cp5m.json
Kendo UI for Angular Editor Component (npm package @progress/kendo-angular-editor) before version 1.2.3 is vulnerable to Cross-Site Scripting. When the Editor content contains potentially malicious scripts in element event handlers, they get executed.
Adding the following content to the Editor value demonstrates the issue: <img src="" onerror=alert(document.domain)>.