{"id":"GHSA-m5jf-8crm-r65m","summary":"Vditor allows Cross-site Scripting via an attribute of an `A` element","details":"Vditor 3.10.3 allows XSS via an attribute of an `A` element.\n\nNOTE: the vendor indicates that a user is supposed to mitigate this via `sanitize=true`.","aliases":["CVE-2024-34449"],"modified":"2024-05-03T20:56:35.060068Z","published":"2024-05-03T18:30:37Z","database_specific":{"github_reviewed_at":"2024-05-03T20:38:15Z","nvd_published_at":"2024-05-03T16:15:11Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34449"},{"type":"WEB","url":"https://github.com/Vanessa219/vditor/issues/1604"},{"type":"PACKAGE","url":"https://github.com/Vanessa219/vditor"},{"type":"WEB","url":"https://github.com/Vanessa219/vditor/blob/b3a14d6e4462b0c17141e1fcc66173264ada64e0/README_en_US.md?plain=1#L310"}],"affected":[{"package":{"name":"vditor","ecosystem":"npm","purl":"pkg:npm/vditor"},"versions":["3.10.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-m5jf-8crm-r65m/GHSA-m5jf-8crm-r65m.json"}}],"schema_version":"1.9.0"}