VDB
Sign up
MEDIUM6.1

GHSA-97x5-cc53-cv4v

Cross site scripting in froala-editor

Quick fix

GHSA-97x5-cc53-cv4v — froala-editor: upgrade to the fixed version with the command below.

npm install froala-editor@4.0.11

Details

A cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor allows attackers to execute arbitrary web scripts or HTML.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/froala-editor
Introduced in: 0Fixed in: 4.0.11
Fixnpm install froala-editor@4.0.11

References