Imperavi · Angular Redactor · CVE-2018-13339
**Name of the Vulnerable Software and Affected Versions**
Angular Redactor version 1.1.6
**Description**
The issue allows for stored XSS attacks when HTML content mode is used in Imperavi Redactor 3. This can be demonstrated through the use of an `onerror` attribute of an `IMG` element.
**Recommendations**
For Angular Redactor version 1.1.6, update to a version that fixes this issue, as using the HTML content mode currently poses a risk of stored XSS attacks.