Junglewise Threat Intelligence

CVE-2016-1000231: emojione cross-site scripting in emoji conversion

CVE-2016-1000231 · Severity: info · CVSS 0 · Published 2020-09-01

Vendors: npm.

Executive brief

emojione is a JavaScript library for converting emoji text into images or HTML. Affected versions fail to properly sanitize user input passed to emoji conversion functions, allowing attackers to inject malicious JavaScript code that executes in the context of web applications using the library. This can lead to session hijacking, credential theft, or defacement of user content. Applications using emojione versions prior to 1.3.1 are at risk.

Technical details

emojione contains a cross-site scripting (CWE-79) vulnerability in its emoji conversion functions: toShort(), shortnameToImage(), unicodeToImage(), and toImage(). The root cause is insufficient input sanitization when processing user-supplied emoji text. Attackers can inject malicious HTML and JavaScript through emoji parameters, and the functions do not properly escape the input before inserting it into the DOM or HTML output. The vulnerability is reachable wherever these functions are called with untrusted user input, typically in web applications processing user-submitted emoji or text. An attacker can execute arbitrary JavaScript in the context of the affected application's domain. The vulnerability was patched in version 1.3.1 (released April 2015) with revised escaping functions.

Affected products

  • joypixels emojione <=1.3.0

Timeline

  • 2020-09-01: disclosed: GHSA-46m8-42hm-wvvw published
  • 2015-04-13: patched: Version 1.3.1 released with security fixes

References