Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

W2Ning

#43024of 53,630
6.1Total CVSS
Vulnerabilities · 1
PT-2021-10802
6.1
2021-10-26
Froala · Froala Wysiwyg Editor · CVE-2020-22864
**Name of the Vulnerable Software and Affected Versions** Froala WYSIWYG Editor version 3.1.0 **Description** A cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor allows attackers to execute arbitrary web scripts or HTML. **Recommendations** For Froala WYSIWYG Editor version 3.1.0, consider disabling the Insert Video function as a temporary workaround until a patch is available. Restrict access to this function to minimize the risk of exploitation.