Junglewise Threat Intelligence

CVE-2020-23849: jsoneditor stored cross-site scripting in tree mode

CVE-2020-23849 · Severity: low · CVSS 3.1 · Published 2021-10-12

Vendors: Jos de Jong, npm.

Executive brief

jsoneditor is a popular JavaScript library used to view and edit JSON data in web applications. A stored cross-site scripting (XSS) vulnerability in the tree mode allows attackers to inject malicious JavaScript code that persists and executes when users view the edited JSON, potentially compromising user sessions or stealing sensitive data.

Technical details

The vulnerability is a stored XSS (CWE-79) in jsoneditor's tree mode that occurs through improper input sanitization when processing JSON data. An attacker can inject arbitrary JavaScript code into JSON values, which is then executed in the browser when the tree is rendered. The attack requires no authentication but does require user interaction (clicking the tree display or input elements). The vulnerable versions are all releases before 9.0.2; the fix is available in version 9.0.2 and later.

Affected products

  • Jos de Jong jsoneditor before 9.0.2

Timeline

  • 2020-07-01: disclosed
  • 2021-10-12: patched: Fix released in version 9.0.2

References

Related threats