VDB
Sign up
MEDIUM5.4

GHSA-25fq-6qgg-qpj8

SCEditor has DOM XSS via emoticon URL/HTML injection

Quick fix

GHSA-25fq-6qgg-qpj8 — sceditor: upgrade to the fixed version with the command below.

npm install sceditor@3.2.1

Details

If an attacker has the ability control configuration options passed to `sceditor.create()`, like `emoticons`, `charset`, etc. then it's possible for them to trigger an XSS attack due to lack of sanitisation of configuration options.

Proof of concept:

```js sceditor.create(textarea, { emoticons: { dropdown: { ':)': { url: 'x" onerror="window.__xss = true' } } } }); ```

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sceditor
Introduced in: 0Fixed in: 3.2.1
Fixnpm install sceditor@3.2.1

References