Cross-Site Scripting Vulnerability in Slab Quill by Quill.js
CVE-2021-3163
6.1MEDIUM
What is CVE-2021-3163?
An XSS vulnerability exists in the HTML editor of Slab Quill version 4.8.0, allowing attackers to inject and execute arbitrary JavaScript by leveraging a crafted 'onloadstart' attribute in an IMG element. This issue does not arise from a flaw in Slab Quill itself but is a result of expected behavior in web browsers, which can lead to unintended script execution if user inputs are not properly sanitized.
