Cross-Site Scripting Vulnerability in Slab Quill by Quill.js
CVE-2021-3163

6.1MEDIUM

Key Information:

Vendor

Slab

Status
Vendor
CVE Published:
12 April 2021

What is CVE-2021-3163?

An XSS vulnerability exists in the HTML editor of Slab Quill version 4.8.0, allowing attackers to inject and execute arbitrary JavaScript by leveraging a crafted 'onloadstart' attribute in an IMG element. This issue does not arise from a flaw in Slab Quill itself but is a result of expected behavior in web browsers, which can lead to unintended script execution if user inputs are not properly sanitized.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.