VDB
Sign up
HIGH8.7

GHSA-qh7x-j4v8-qw5w

Clipboard-based XSS

Quick fix

GHSA-qh7x-j4v8-qw5w — jsuites: upgrade to the fixed version with the command below.

npm install jsuites@4.9.11

Details

### Impact XSS against the user.

### Details jsuites is vulnerable to DOM based XSS if the user can be tricked into copying _anything_ from a malicious and pasting it into the html editor. This is because a part of the clipboard content is directly written to `innerHTML` causing XSS.

### References The Curious Case of Copy & Paste – on risks of pasting arbitrary content in browsers: https://research.securitum.com/the-curious-case-of-copy-paste/

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jsuites
Introduced in: 0Fixed in: 4.9.11
Fixnpm install jsuites@4.9.11

References