QID 980516
QID 980516: Nodejs (npm) Security Update for froala-editor (GHSA-cq6w-w5rj-p9x8)
Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads to persistent Cross-site scripting (XSS) vulnerability within the hyperlink creation module.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cq6w-w5rj-p9x8 for updates pertaining to this vulnerability.
Vendor References
- GHSA-cq6w-w5rj-p9x8 -
github.com/advisories/GHSA-cq6w-w5rj-p9x8
CVEs related to QID 980516
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cq6w-w5rj-p9x8 | froala-editor |
|