MEDIUM5.4
GHSA-25fq-6qgg-qpj8
SCEditor has DOM XSS via emoticon URL/HTML injection
Quick fix
GHSA-25fq-6qgg-qpj8 — sceditor: upgrade to the fixed version with the command below.
npm install sceditor@3.2.1Details
If an attacker has the ability control configuration options passed to `sceditor.create()`, like `emoticons`, `charset`, etc. then it's possible for them to trigger an XSS attack due to lack of sanitisation of configuration options.
Proof of concept:
```js sceditor.create(textarea, { emoticons: { dropdown: { ':)': { url: 'x" onerror="window.__xss = true' } } } }); ```
Are you affected?
Enter the version of the package you're using.