First published: Mon Apr 05 2021(Updated: )
Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads to persistent Cross-site scripting (XSS) vulnerability within the hyperlink creation module.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Froala WYSIWYG Editor | =3.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-30109 is a Cross Site Scripting (XSS) vulnerability in Froala Editor 3.2.6.
CVE-2021-30109 allows for persistent XSS attacks within the hyperlink creation module.
The severity of CVE-2021-30109 is medium, with a CVSS score of 6.1.
There is no known fix or patch for CVE-2021-30109. It is recommended to update to a version of Froala Editor that is not affected by this vulnerability.
You can find more information about CVE-2021-30109 at the following references: [Froala Website](http://froala.com) and [CVE-2021-30109 GitHub Repository](https://github.com/Hackdwerg/CVE-2021-30109/blob/main/README.md).