Intel

AIKIDO-2024-10064

froala-editor is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2023-41592 Published Apr 29, 2024

54

Medium Risk

This Affects:

JSfroala-editor
4.0.1 - 4.1.3
Fixed in 4.1.4
Are you affected? Scan for Free

TL;DR

Froala Editor versions v4.0.1 to v4.1.3 were found to contain a Cross-site Scripting (XSS) vulnerability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

froala-editor is vulnerable to Cross-site Scripting (XSS) in versions 4.0.1 - 4.1.3.

How to fix this

Upgrade the froala-editor library to the patch version.