Advisories for Npm/Ckeditor-Dev package

2018

Cross-site Scripting

Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor allows remote attackers to inject arbitrary web script through a crafted IMG element.