Executive brief
Margox braft-editor is a rich text editor library used to build content editing interfaces in web applications. A cross-site scripting (XSS) vulnerability in the embed media feature allows attackers to inject malicious scripts that execute in the context of users' browsers, potentially stealing session cookies, hijacking user accounts, or defacing content within the editor.
Technical details
The vulnerability is a reflected/stored XSS (CWE-79) in the embed media renderer component (braft-editor/src/renderers/atomics/Embed/index.jsx). The root cause is unsafe use of dangerouslySetInnerHTML with unsanitized user input from the URL field; when a user inserts malicious HTML such as <img/src=1 onerror=alert(1)> via the media embed dialog and clicks insert, the unescaped payload is rendered directly into the DOM. Attack vector is network-based, requiring user interaction (editor interaction and clicking insert), and no authentication is required. An attacker can execute arbitrary JavaScript in the victim's browser context. The vulnerability affects braft-editor through version 2.3.8; patch status and fixed versions are not specified in available sources.
Affected products
- Margox braft-editor through 2.3.8
Timeline
- 2021-02-19: disclosed: Vulnerability reported in GitHub issue #880
- 2023-08-11: advisory: GHSA-jfrf-vv54-j2jg published; CVE-2021-27524 assigned