GHSA-h236-g5gh-vq6c

    Dashboard / Vulnerabilities / GHSA-h236-g5gh-vq6c

    GHSA-h236-g5gh-vq6c

    Published: 10 Feb 2022Last Modified: 8 Nov 2023

    Summary: DOM-based cross-site scripting in Froala Editor

    Details: Froala WYSIWYG HTML Editor is a lightweight WYSIWYG HTML Editor written in JavaScript that enables rich text editing capabilities for web applications. A DOM-based cross-site scripting (XSS) vulnerability exists in versions before 3.2.3 because HTML code in the editor is not correctly sanitized when inserted into the DOM. This allows an attacker that can control the editor content to execute arbitrary JavaScript in the context of the victim’s session.

    Affected packages

    Package

    Name: froala-editor

    Purl: pkg:npm/froala-editor

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -3.2.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-h236-g5gh-vq6c | CVE-DB