Junglewise Threat Intelligence

CVE-2021-30109: Froala Editor cross-site scripting in hyperlink creation

CVE-2021-30109 · Severity: low · CVSS 3.1 · Published 2021-10-06

Technologies: froala-editor (npm), Froala Editor. Vendors: npm, Froala.

Executive brief

Froala Editor is a popular rich-text editor component used in web applications. A flaw in the hyperlink creation feature allows attackers to inject malicious JavaScript code that persists in documents. An attacker could exploit this to steal user credentials, deface content, or hijack user sessions.

Technical details

Froala Editor 3.2.6 contains a persistent XSS vulnerability (CWE-79) in the hyperlink creation module. The vulnerability is triggered when a specially crafted base64-encoded string is processed during hyperlink creation. The attack requires user interaction (opening/editing a malicious hyperlink) but does not require authentication. Once injected, the XSS payload persists in the document, affecting all users who view or edit that content. The vulnerability has been fixed in later versions.

Affected products

  • Froala Editor 3.2.6 and earlier

Timeline

  • 2021-04-05: disclosed
  • 2021-10-06: advisory
  • patched: Fix available in versions after 3.2.6

References

Related threats