CVE-2022-23461

Source
https://cve.org/CVERecord?id=CVE-2022-23461
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23461.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-23461
Aliases
Published
2022-09-24T03:05:08Z
Modified
2026-03-14T11:32:26.474162Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Cross-Site Scripting (XSS) in Jodit Editor
Details

Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vulnerable to XSS attacks when pasting specially constructed input. This issue has not been fully patched. There are no known workarounds.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23461.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "3.0.0"
            },
            {
                "last_affected": "3.20.4"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23461.json"