CVE-2021-3163: XSS

Published Apr 12, 2021
·
Updated

DISPUTED A vulnerability in the HTML editor of Slab Quill 4.8.0 allows an attacker to execute arbitrary JavaScript by storing an XSS payload (a crafted onloadstart attribute of an IMG element) in a text field. Note: Researchers have claimed that this issue is not within the product itself, but is intended behavior in a web browser.

Other sources

A vulnerability in the HTML editor of Slab Quill allows an attacker to execute arbitrary JavaScript by storing an XSS payload (a crafted onloadstart attribute of an IMG element) in a text field. No patch exists and no further releases are planned.

This CVE is disputed. Researchers have claimed that this issue is not within the product itself, but is intended behavior in a web browser. More information can be found here.

GitHub

Affected Software

2 affected components
Slab Quill Node.js=4.8.0
npm/quill<=1.3.7

Event History

Apr 12, 2021
CVE Published
via MITRE·08:35 PM
Data Sourced
via MITRE·08:35 PM
Description
Disputed
09:15 PM
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
May 10, 2021
Advisory Published
via GitHub·03:38 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2021-3163?

The severity of CVE-2021-3163 is currently disputed, as researchers have indicated that the issue may not be inherent to the product itself.

2

How do I fix CVE-2021-3163?

To mitigate CVE-2021-3163, ensure that you sanitize user inputs properly to prevent the injection of malicious JavaScript.

3

What software is affected by CVE-2021-3163?

CVE-2021-3163 affects Slab Quill version 4.8.0 and npm package quill up to version 1.3.7.

4

What type of vulnerability is CVE-2021-3163?

CVE-2021-3163 is a vulnerability that allows for cross-site scripting (XSS) attacks via arbitrary JavaScript execution.

5

Can CVE-2021-3163 be exploited remotely?

Yes, CVE-2021-3163 can be exploited remotely if the attacker can manipulate text fields to include malicious payloads.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203