VDB
Sign up
MEDIUM5.4

GHSA-9hfw-cvf4-5x25

wangEditor was discovered to contain a cross-site scripting (XSS) vulnerability via the image upload function

Quick fix

GHSA-9hfw-cvf4-5x25 — @wangeditor/editor: upgrade to the fixed version with the command below.

npm install @wangeditor/editor@4.7.12

Details

There is a cross-site scripting (XSS) issue in wangEditor via the image upload function in version 4.7.11. This issue has been fixed in version 4.7.12.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@wangeditor/editor
Introduced in: 0Fixed in: 4.7.12
Fixnpm install @wangeditor/editor@4.7.12

References