Description
Premium Software CLEditor 1.4.5 and earlier is affected by: Cross Site Scripting (XSS). The impact is: An attacker might be able to inject arbitrary html and script code into the web site. The component is: jQuery plug-in. The attack vector is: the victim must open a crafted href attribute of a link (A) element.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0593 | Premium Software CLEditor 1.4.5 and earlier is affected by: Cross Site Scripting (XSS). The impact is: An attacker might be able to inject arbitrary html and script code into the web site. The component is: jQuery plug-in. The attack vector is: the victim must open a crafted href attribute of a link (A) element. |
Github GHSA |
GHSA-hh56-x62g-gvhc | Cross-site scripting in CLEditor |
References
History
No history.
Status: PUBLISHED
Assigner: dwf
Published:
Updated: 2024-08-05T03:07:17.997Z
Reserved: 2019-03-20T00:00:00.000Z
Link: CVE-2019-1010113
No data.
Status : Modified
Published: 2019-07-19T16:15:12.180
Modified: 2024-11-21T04:17:58.730
Link: CVE-2019-1010113
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA