CVE-2024-34449
Vditor allows Cross-site Scripting via an attribute of an `A` element
EPSS 0.19%
Description
Vditor 3.10.3 allows XSS via an attribute of an `A` element. NOTE: the vendor indicates that a user is supposed to mitigate this via `sanitize=true`.
How to fix CVE-2024-34449
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- npm/vditor—no fix listed
Is CVE-2024-34449 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.