From 5ad378905e90f444e65ab766fb011a2f97ac6ca2 Mon Sep 17 00:00:00 2001 From: Samkit Shah Date: Mon, 20 Sep 2021 18:43:35 +0530 Subject: [PATCH] Update ckeditor.js to prevent XSS vulnerability For CKEditor 4.6.2 version, XSS vulnerability is there: https://snyk.io/vuln/npm:ckeditor@4.6.2 So changing defaultScriptUrl from https://cdn.ckeditor.com/4.6.2/standard/ckeditor.js to https://cdn.ckeditor.com/4.12.1/standard/ckeditor.js --- src/ckeditor.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/ckeditor.js b/src/ckeditor.js index e703048..a4954f8 100644 --- a/src/ckeditor.js +++ b/src/ckeditor.js @@ -3,7 +3,7 @@ import PropTypes from 'prop-types'; import ReactDOM from 'react-dom'; const loadScript = require('load-script'); -var defaultScriptUrl = 'https://cdn.ckeditor.com/4.6.2/standard/ckeditor.js'; +var defaultScriptUrl = 'https://cdn.ckeditor.com/4.12.1/standard/ckeditor.js'; /** * @author codeslayer1