Executive brief
Pandao editor.md is a popular open-source JavaScript markdown editor used to render and edit markdown content in web applications. The editor fails to properly sanitize IMG tag attributes, allowing attackers to inject malicious scripts that execute in the context of the editor. This could enable account takeover or malicious actions if a CMS using this editor is attacked.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw in editor.md version 1.5.0 caused by insufficient input sanitization of IMG element attributes. Attackers can craft malicious IMG tags with event handlers (e.g., onerror) in the attributes to bypass the editor's filtering mechanisms. The attack requires user interaction (viewing or rendering attacker-supplied markdown content) but does not require authentication. A successful exploit allows arbitrary JavaScript execution in the victim's browser with the privileges of the logged-in user, potentially leading to session hijacking, credential theft, or administrative actions in CMS systems integrating this editor.
Affected products
- Pandao editor.md 1.5.0
Timeline
- 2018-08-16: disclosed
- 2018-09-06: advisory