VDB
Sign up
MEDIUM5.4

GHSA-rr6v-h7m8-wc9f

Cross-site Scripting in Froala WYSIWYG Editor

Quick fix

GHSA-rr6v-h7m8-wc9f — froala/wysiwyg-editor: upgrade to the fixed version with the command below.

composer require froala/wysiwyg-editor:^3.2.7

Details

Froala WYSIWYG Editor 3.2.6-1 is affected by XSS due to a namespace confusion during parsing.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/froala/wysiwyg-editor
Introduced in: 0Fixed in: 3.2.7
Fixcomposer require froala/wysiwyg-editor:^3.2.7

References