Issue #1598Opened November 20, 2018by kewilson0 reactions

[Bug] Security Vulnerability Detected

Question

Hi, our SAST scanner detected the following, thought you might like to know.

https://raw.githubusercontent.com/artf/grapesjs/dev/dist/grapes.js

Code (Line #29702): this.setElement(this.createElement(.result(this, 'tagName')));

Client_DOM_Stored_XSS exists @ public/dist/grapes.js Severity: High CWE: 79 https://cwe.mitre.org/data/definitions/79.html

Answers (2)

artfNovember 21, 20180 reactions

Thanks for the report @kewilson but that line is totally legit for the editor. The library itself shouldn't be "able to hurt", most of the vulnerabilities might be added during the integration

lock[bot]November 21, 20190 reactions

This thread has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

Related Questions and Answers

Continue research with similar issue discussions.

Paid Plugins That Match This Issue

Curated by issue keywords and label relevance to help you ship faster.

View all plugins

Loading paid plugin recommendations...

Browse Plugin Categories

Jump directly to plugin category pages on the marketplace.