Imperavi Redactor 3 in Angular Redactor 1.1.6, when HTML content mode is used, allows stored XSS, as demonstrated by an onerror attribute of an IMG element, a related issue to CVE-2018-7035.
{
"extracted_events": [
{
"introduced": "1.1.6"
},
{
"last_affected": "1.1.6"
}
],
"source": "CPE_STRING",
"cpe": "cpe:2.3:a:angular_redactor_project:angular_redactor:1.1.6:*:*:*:*:*:*:*"
}