Vulnerabilities/

Cross-site Scripting in quill

Severity:
Medium

Description

A vulnerability in the HTML editor of Slab Quill allows an attacker to execute arbitrary JavaScript by storing an XSS payload (a crafted onloadstart attribute of an IMG element) in a text field. No patch exists and no further releases are planned.

This CVE is disputed.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
quill
Anything's wrong? Let us know Last updated on August 09, 2024

This issue is available in SmartScanner Professional

See Pricing