Vulnerabilities/

DOM-based cross-site scripting in Froala Editor

Severity:
Medium

Description

Froala WYSIWYG HTML Editor is a lightweight WYSIWYG HTML Editor written in JavaScript that enables rich text editing capabilities for web applications. A DOM-based cross-site scripting (XSS) vulnerability exists in versions before 3.2.3 because HTML code in the editor is not correctly sanitized when inserted into the DOM.

Recommendation

Update the froala-editor package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
froala-editor
Anything's wrong? Let us know Last updated on January 29, 2023

This issue is available in SmartScanner Professional

See Pricing