Description
Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads to persistent Cross-site scripting (XSS) vulnerability within the hyperlink creation module.
Remediation
References
http://froala.com
https://github.com/Hackdwerg/CVE-2021-30109/blob/main/README.md
Related Vulnerabilities
CVE-2022-4742 Vulnerability in maven package org.webjars.npm:json-pointer
CVE-2017-16138 Vulnerability in npm package mime
CVE-2021-3597 Vulnerability in maven package io.undertow:undertow-core
CVE-2018-1273 Vulnerability in maven package org.springframework.data:spring-data-commons
CVE-2023-42503 Vulnerability in maven package org.apache.commons:commons-compress