CVE-2018-18909

xhEditor 1.2.2 allows XSS via JavaScript code in the SRC attribute of an IFRAME element within the editor's source-code view.
References
Link Resource
https://github.com/yaniswang/xhEditor/issues/37 Exploit Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:xheditor:xheditor:1.2.2:*:*:*:*:*:*:*

Information

Published : 2018-11-03 04:29

Updated : 2018-12-11 04:27


NVD link : CVE-2018-18909

Mitre link : CVE-2018-18909

Products Affected
No products.
CWE