Intel

AIKIDO-2024-10168

ngx-quill is vulnerable to Improper Use of Validation Framework

Improper Use of Validation Framework Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 4, 2024

60

Medium Risk

This Affects:

jsngx-quill
10.0.0 - 26.0.4
Fixed in 26.0.5
Are you affected? Scan for Free

TL;DR

Affected versions of this package unintentionally ignore the global QuillEditorComponent sanitation setting, causing HTML input to remain unsanitized.

Who does this affect?

You are affected if you are using a vulnerable version of the package and the global sanitation setting is set to true.

Background info

ngx-quill is vulnerable to Improper Use of Validation Framework in versions 10.0.0 - 26.0.4.

How to fix this

Upgrade the ngx-quill library to the patch version or set the property on component level.