Vulnerabilities/

Angular Redactor XSS Vulnerability

Severity:
Medium

Description

Imperavi Redactor 3 in Angular Redactor 1.1.6, when HTML content mode is used, allows stored XSS, as demonstrated by an onerror attribute of an IMG element, a related issue to CVE-2018-7035.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
angular-redactor
Anything's wrong? Let us know Last updated on October 06, 2023