CVE-2018-14037: Cross-site Scripting
(updated )
Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor allows remote attackers to inject arbitrary JavaScript into the DOM of the WYSIWYG editor because of the editorNS.Serializer
toEditableHtml
function in kendo.all.min.js
. If the victim accesses the editor, the payload would be executed.
References
Detect and mitigate CVE-2018-14037 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →