First published: Fri Jul 16 2021(Updated: )
Froala WYSIWYG Editor 3.2.6-1 is affected by XSS due to a namespace confusion during parsing.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/froala/wysiwyg-editor | <3.2.7 | 3.2.7 |
Froala WYSIWYG Editor | <3.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28114 is a vulnerability in Froala WYSIWYG Editor 3.2.6-1 that allows for cross-site scripting (XSS) attacks due to a namespace confusion during parsing.
CVE-2021-28114 affects Froala WYSIWYG Editor 3.2.6-1 by enabling attackers to execute malicious scripts through a namespace confusion during parsing.
The severity of CVE-2021-28114 is medium with a severity value of 5.4.
To fix CVE-2021-28114, upgrade to Froala WYSIWYG Editor version 3.2.7 or higher.
You can find more information about CVE-2021-28114 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-28114), [Froala WYSIWYG Editor](https://froala.com/wysiwyg-editor/), [Bishop Fox](https://labs.bishopfox.com/advisories/froala-editor-v3.2.6).