CVE

Id
103409  
CVE No.
CVE-2017-6589  
Status
Candidate  
Description
EpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example attack vector is a crafted IMG element in an HTML document.  
Phase
Assigned (20170309)  
Votes
None (candidate not yet proposed)  
Comments