kolkov / angular-editor

A simple native WYSIWYG editor component for Angular 6 -14+
https://angular-editor.kolkov.ru
MIT License
676 stars 360 forks source link

[ Critical Security Vulnerability ] XSS #529

Open Bkmaxx opened 1 year ago

Bkmaxx commented 1 year ago

Critical Vulnerability of cross-site scripting can be triggered by using simple html image tag which will trigger javascript code on onerror event and can compromise client side renderring that view..

thalles63 commented 5 months ago

Any update on this?