501stLegionA3 / FiveOhFirstDataCore

A Web App designed to manage the 501st Legion StarSim Roster.
https://dc.501stlegion-a3.com/
MIT License
8 stars 12 forks source link

Security: CKEditor5 cross-site scripting #413

Open LaocheXe opened 1 year ago

LaocheXe commented 1 year ago

More of a question, than an issue. But getting Security alerts about known security vulnerabilities.

Dependency: @ckeditor/ckeditor5-html-support Our Version < 35.0.1 Upgrade Version: ~> 35.0.1

Defined in: package.json

I don't know what changes they made to the ckeditor (besides security update) - so I don't know if upgrading to the new current/updated version would cause an issues or not. I would like if it someone could test that out - I would but I need a new SSD/HDD to store the data/programs to test/build on this some more.