Vulnerabilities/

Cross-Site Scripting in @ckeditor/ckeditor5-link

Severity:
Medium

Description

Versions of status-board prior to 10.0.1 are vulnerable to Cross-Site Scripting. The _createPreviewButton() function fails to sanitize the href attribute of a created <a> tag. This may allow attackers to execute arbitrary JavaScript in a victim’s browser.

Recommendation

Update the @ckeditor/ckeditor5-link package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@ckeditor/ckeditor5-link
Anything's wrong? Let us know Last updated on May 01, 2023