Drupal 8 Updated to Patch Flaw in WYSIWYG Editor

Updates released on Wednesday for Drupal 8 patch a moderately critical cross-site scripting (XSS) vulnerability affecting a third-party JavaScript library.

The flaw impacts CKEditor, a WYSIWYG HTML editor included in the Drupal core. CKEditor exposes users to XSS attacks due to a flaw in the Enhanced Image (image2) plugin.

read more

Read more: Drupal 8 Updated to Patch Flaw in WYSIWYG Editor

Story added 19. April 2018, content source with full text you can find at link above.