Description
Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.
Remediation
References
https://github.com/strapi/strapi/pull/8440
https://github.com/strapi/strapi/releases/tag/v3.2.5
Related Vulnerabilities
CVE-2020-15152 Vulnerability in npm package ftp-srv
CVE-2022-36036 Vulnerability in npm package mdx-mermaid
CVE-2019-15302 Vulnerability in npm package cryptpad
CVE-2016-10735 Vulnerability in maven package org.jszip.redist:bootstrap
CVE-2023-33246 Vulnerability in maven package org.apache.rocketmq:rocketmq-broker