QID 981364

QID 981364: Nodejs (npm) Security Update for quill (GHSA-4943-9vgg-gr5r)

A vulnerability in the HTML editor of Slab Quill allows an attacker to execute arbitrary JavaScript by storing an XSS payload (a crafted onloadstart attribute of an IMG element) in a text field. No patch exists and no further releases are planned.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-4943-9vgg-gr5r for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981364

    Software Advisories
    Advisory ID Software Component Link
    GHSA-4943-9vgg-gr5r quill URL Logo github.com/advisories/GHSA-4943-9vgg-gr5r