Intel

AIKIDO-2024-10070

angular-froala-wysiwyg is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2023-41592 Published May 1, 2024

54

Medium Risk

This Affects:

JSangular-froala-wysiwyg
4.0.1 - 4.1.3
Fixed in 4.1.4
Are you affected? Scan for Free

TL;DR

Froala Editor v4.0.1 to v4.1.3 was discovered to contain a cross-site scripting (XSS) vulnerability.

Who does this affect?

You're affected if you are using a version which is within vulnerability ranges.

Background info

angular-froala-wysiwyg is vulnerable to Cross-site Scripting (XSS) in versions 4.0.1 - 4.1.3.

How to fix this

Upgrade angular-froala-wysiwyg library to patch version.