Описание
React Draft Wysiwyg Cross-Site Scripting (XSS) via the Embedded Button
All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the tag.
Пакеты
Наименование
react-draft-wysiwyg
npm
Затронутые версииВерсия исправления
<= 1.15.0
Отсутствует
Связанные уязвимости
CVSS3: 6.1
nvd
10 месяцев назад
All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the <iframe> tag.