MEDIUM5.4
GHSA-cxm3-v4mv-6mh8
vditor Vulnerable to Cross-site Scripting in SVG events
Quick fix
GHSA-cxm3-v4mv-6mh8 — vditor: upgrade to the fixed version with the command below.
npm install vditor@3.8.11Details
vditor does not filter user input in SVG events, leading to XSS
### PoC
```html </a> <svg><animate onbegin=alert(11) attributeName=x dur=1s> ```
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-4103[ADVISORY]
- https://github.com/Vanessa219/vditor/issues/1133[WEB]
- https://github.com/vanessa219/vditor/commit/8d4d0889dd72b2f839e93a49db3da3a370416c7d[WEB]
- https://github.com/vanessa219/vditor[PACKAGE]
- https://huntr.dev/bounties/67b980af-7357-4879-9448-a926c6474225[WEB]