Executive brief
jqTree is a JavaScript library that provides interactive tree UI components for web applications. A cross-site scripting (XSS) vulnerability in the drag-and-drop feature allows attackers to inject malicious scripts into tree nodes; when users drag these nodes, the scripts execute in their browsers, potentially stealing credentials or session data.
Technical details
The vulnerability is a stored/DOM-based XSS flaw in jqTree's drag-and-drop functionality for modifying tree hierarchy. The vulnerable component fails to properly sanitize or escape node labels that contain script payloads (e.g., <img src=x onerror=alert()>). When a user drags a node to a new position, the malicious script within the node label is executed in the user's browser. No authentication is required; any user with access to a page using vulnerable jqTree code is at risk. The fix is available in version 1.3.4 and later.
Affected products
- jqTree jqTree <1.3.4
Timeline
- 2016-07-12: disclosed: Issue opened on GitHub
- 2020-09-01: advisory: GHSA-gjhx-gxwx-jx9j published