MEDIUM6.1
GHSA-97x5-cc53-cv4v
Cross site scripting in froala-editor
Quick fix
GHSA-97x5-cc53-cv4v — froala-editor: upgrade to the fixed version with the command below.
npm install froala-editor@4.0.11Details
A cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor allows attackers to execute arbitrary web scripts or HTML.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-22864[ADVISORY]
- https://github.com/froala/wysiwyg-editor/issues/3880[WEB]
- https://github.com/418sec/wysiwyg-editor/pull/1[WEB]
- https://github.com/froala/wysiwyg-editor/pull/3911[WEB]
- https://github.com/froala/wysiwyg-editor[PACKAGE]
- https://github.com/froala/wysiwyg-editor/releases/tag/v4.0.11[WEB]
- https://www.youtube.com/watch?v=WE3b1iSnWJY[WEB]