MEDIUM6.1
GHSA-qrhq-x7xh-2784
Froala WYSIWYG Editor XSS Vulnerability
Quick fix
GHSA-qrhq-x7xh-2784 — froala/wysiwyg-editor: upgrade to the fixed version with the command below.
composer require froala/wysiwyg-editor:^3.2.2Details
Froala Editor before 3.2.2 allows XSS via pasted content.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/froala/wysiwyg-editor
Introduced in:
0Fixed in: 3.2.2Fix
composer require froala/wysiwyg-editor:^3.2.2