Junglewise Threat Intelligence

CVE-2021-4103: vditor cross-site scripting in SVG events

CVE-2021-4103 · Severity: low · CVSS 3.1 · Published 2022-01-28

Technologies: Vanessa219 Vditor. Vendors: npm.

Executive brief

vditor is a popular open-source Markdown editor used in web applications. The vulnerability allows attackers to inject malicious JavaScript code through SVG event attributes, which are not properly sanitized. If an application using vditor processes untrusted user input, an attacker can execute arbitrary JavaScript in the context of other users' browsers, leading to account compromise, data theft, or malware delivery.

Technical details

vditor fails to sanitize event attributes in SVG elements, specifically allowing `onbegin` and similar event handlers in SVG tags. The vulnerability is a classic reflected/stored cross-site scripting (XSS) flaw (CWE-79) that requires user interaction to trigger—typically when a victim views or interacts with content containing the malicious SVG. An attacker can craft a payload like `<svg><animate onbegin=alert(11) attributeName=x dur=1s>` and inject it through the editor. The attack vector is network-based with low attack complexity, though it requires authenticated user context and user interaction. The vulnerability was patched in version 3.8.11; all versions prior to this are affected.

Affected products

  • Vanessa219 vditor before 3.8.11

Timeline

  • 2021-12-12: disclosed: Issue reported on huntr.dev
  • 2022-01-23: advisory: CVE-2021-4103 published by NVD
  • 2022-01-28: patched: GHSA advisory published; fix available in version 3.8.11

References

Related threats