VDB
Sign up
MEDIUM6.1

GHSA-fq5x-7292-2p5r

React Draft Wysiwyg Cross-Site Scripting (XSS) via the Embedded Button

Details

All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the <iframe> tag.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/react-draft-wysiwyg
Introduced in: 0

No fixed version published yet for react-draft-wysiwyg (npm). Pin to a known-safe version or switch to an alternative.

References