Description
Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.
Remediation
References
https://github.com/strapi/strapi/pull/8440
https://github.com/strapi/strapi/releases/tag/v3.2.5
Related Vulnerabilities
CVE-2022-21802 Vulnerability in maven package org.webjars.npm:grapesjs
CVE-2020-28429 Vulnerability in npm package geojson2kml
CVE-2022-24196 Vulnerability in maven package com.itextpdf:itext7-core
CVE-2021-26540 Vulnerability in npm package sanitize-html
CVE-2022-28157 Vulnerability in maven package com.surenpi.jenkins:phoenix-autotest