MEDIUM
All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the <iframe> tag
Published Apr 4, 2025
5.1
MEDIUMCVSS 4.0
EPSS 0.24%
Description
Affected products
Remediation
References (4)
Change history (0)
No recorded changes yet.