Description
Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.
Remediation
References
https://github.com/strapi/strapi/pull/8440
https://github.com/strapi/strapi/releases/tag/v3.2.5
Related Vulnerabilities
CVE-2022-0235 Vulnerability in npm package node-fetch
CVE-2021-21422 Vulnerability in npm package mongo-express
CVE-2021-43803 Vulnerability in npm package next
CVE-2023-36478 Vulnerability in maven package org.eclipse.jetty:jetty-http
CVE-2021-41182 Vulnerability in maven package org.webjars:jquery-ui