In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froala richeditor could result in a successful self-XSS attack. This has been fixed in 1.0.467.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| october/backend(Packagist) | 1.0.319 | 1.0.467 | N/A |
CVSS Metrics