Executive brief
Simditor is a browser-based rich text editor used in web applications. A cross-site scripting (XSS) vulnerability allows attackers to inject malicious code through crafted SVG elements in text fields, potentially stealing user session data or performing actions on behalf of affected users.
Technical details
Simditor v2.3.11 and earlier contain a DOM-based cross-site scripting (CWE-79) vulnerability in TEXTAREA element processing. The vulnerability arises from insufficient sanitization of SVG tags with event handlers (e.g., svg/onload=alert) embedded in user-supplied content. An attacker can craft a malicious document or webpage that, when edited in Simditor, executes arbitrary JavaScript in the victim's browser context. The attack requires user interaction (opening and editing a crafted document) and relies on the stored/reflected XSS payload persisting in the editor's output. No information on patch availability is currently documented.
Affected products
- Heartway Simditor 2.3.11 and earlier
Timeline
- 2018-01-31: disclosed
- 2022-05-13: advisory