QID 981364
QID 981364: Nodejs (npm) Security Update for quill (GHSA-4943-9vgg-gr5r)
A vulnerability in the HTML editor of Slab Quill allows an attacker to execute arbitrary JavaScript by storing an XSS payload (a crafted onloadstart attribute of an IMG element) in a text field. No patch exists and no further releases are planned.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4943-9vgg-gr5r for updates pertaining to this vulnerability.
Vendor References
- GHSA-4943-9vgg-gr5r -
github.com/advisories/GHSA-4943-9vgg-gr5r
CVEs related to QID 981364
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4943-9vgg-gr5r | quill |
|