Safety vulnerability ID: 62734
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Django Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability.
https://hacker.soarescorp.com/cve/2023-41592/
Latest version: 4.3.1
django-froala-editor package helps integrate Froala WYSIWYG HTML editor with Django.
- Fixed, cursor jumps when editing inputs inside a table while editor is configured for `toolbarInline`
- Fixed, CVE-2023-41592 XSS vulnerability
- Fixed, text color hex codes are not changing the text color in the editor
- Fixed, page scrolls when we past large content with images in the editor
- Fixed, cross-site scripting vulnerability in Froala Editor 4.1.2 / CVE-2023-43263
- Fixed, changing text color or background causes loss of focus on selected text due to clicking the input
- Fixed, `toolbarSticky` does not work as expected
- Fixed, scrolling issue: pressing Enter scrolls window up when cursor is placed before specific text
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application