VDB
Sign up
MEDIUM5.4

GHSA-hvpq-7vcc-5hj5

Froala Editor Cross-site Scripting vulnerability

Quick fix

GHSA-hvpq-7vcc-5hj5 — froala/wysiwyg-editor: upgrade to the fixed version with the command below.

composer require froala/wysiwyg-editor:^4.1.4

Details

Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/froala/wysiwyg-editor
Introduced in: 4.0.1Fixed in: 4.1.4
Fixcomposer require froala/wysiwyg-editor:^4.1.4
npm/froala-editor
Introduced in: 4.0.1Fixed in: 4.1.4
Fixnpm install froala-editor@4.1.4

References