OverviewStarting in 24.2, the Styled Text Editor Component is available directly in the product. Consider using this in place of the plug-in moving forward. For more information, review: https://docs.appian.com/suite/help/latest/Styled_Text_Editor_Component.html
Visit https://community.appian.com/w/the-appian-playbook/1378/end-user-rich-text-editor-component for more information. If you have any problems installing or using the component, please see the https://community.appian.com/w/the-appian-playbook/1603/rich-text-editor-component-plug-in-troubleshooting-guide
Key Features & Functionality
Supported Browsers: Chrome, Firefox, Edge, SafariSupported on Mobile
Hi Team,
We found one medium security risk vulnerability when we run the scan,
Vulnerability id-BDSA-2021-1834
can you fix this from your end.
Please provide more details about that vulnerability. If this is a CVE, it would be helpful if you could link to it on https://cve.mitre.org/. I tried searching for "BDSA-2021-1834" but got no results.
We have this same vulnerability reported on latest May 2024 scan. Can we have a resolution for this issue.
BDSA-2021-1834
Quill is vulnerable to stored cross-site scripting (XSS) because it does not correctly sanitize user input before it is processed. An attacker could exploit this flaw to execute malicious JavaScript code in a victim's browser, which can result in the theft of session tokens or cookies. **Note**: the vendor disputes this issue, asserting that potentially dangerous content should be sanitized before being passed and loaded into the Quill editor.