{"id":"GHSA-2j5v-fc74-j9q2","summary":"Cross-Site Scripting in editor.md","details":"All versions of `editor.md` are vulnerable to Cross-Site Scripting. User input is insufficiently sanitized, allowing attackers to inject malicious code in payloads containing  base64-encoded content.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative module until a fix is made available.","aliases":["CVE-2019-9737"],"modified":"2023-11-08T04:01:47.648554Z","published":"2019-03-14T15:38:56Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T20:52:22Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-9737"},{"type":"WEB","url":"https://github.com/pandao/editor.md/issues/662"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2j5v-fc74-j9q2"},{"type":"WEB","url":"https://www.npmjs.com/advisories/794"}],"affected":[{"package":{"name":"editor.md","ecosystem":"npm","purl":"pkg:npm/editor.md"},"versions":["1.5.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/03/GHSA-2j5v-fc74-j9q2/GHSA-2j5v-fc74-j9q2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}