MEDIUM 6.1 npm
Cross site scripting in froala-editor
GHSA-97x5-cc53-cv4v · CVE-2020-22864
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
A cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor allows attackers to execute arbitrary web scripts or HTML.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2020-22864
- WEB https://github.com/froala/wysiwyg-editor/issues/3880
- WEB https://github.com/418sec/wysiwyg-editor/pull/1
- WEB https://github.com/froala/wysiwyg-editor/pull/3911
- PACKAGE https://github.com/froala/wysiwyg-editor
- WEB https://github.com/froala/wysiwyg-editor/releases/tag/v4.0.11
- WEB https://www.youtube.com/watch?v=WE3b1iSnWJY
Ready to move
Start Securing
Free, no credit card | First findings in minutes