CVE-2020-22864

MEDIUM6.1EPSS 0.36%

Cross site scripting in froala-editor

Published: 10/28/2021Modified: 11/8/2023
Also known as:GHSA-97x5-cc53-cv4v

Description

A cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor allows attackers to execute arbitrary web scripts or HTML.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (7)