Junglewise Threat Intelligence

CVE-2016-1000234: jqTree cross-site scripting in drag and drop

CVE-2016-1000234 · Severity: info · CVSS 0 · Published 2020-09-01

Vendors: npm.

Executive brief

jqTree is a JavaScript library that provides interactive tree UI components for web applications. A cross-site scripting (XSS) vulnerability in the drag-and-drop feature allows attackers to inject malicious scripts into tree nodes; when users drag these nodes, the scripts execute in their browsers, potentially stealing credentials or session data.

Technical details

The vulnerability is a stored/DOM-based XSS flaw in jqTree's drag-and-drop functionality for modifying tree hierarchy. The vulnerable component fails to properly sanitize or escape node labels that contain script payloads (e.g., <img src=x onerror=alert()>). When a user drags a node to a new position, the malicious script within the node label is executed in the user's browser. No authentication is required; any user with access to a page using vulnerable jqTree code is at risk. The fix is available in version 1.3.4 and later.

Affected products

  • jqTree jqTree <1.3.4

Timeline

  • 2016-07-12: disclosed: Issue opened on GitHub
  • 2020-09-01: advisory: GHSA-gjhx-gxwx-jx9j published

References