Executive brief
jsuites is a JavaScript library providing HTML editor and data manipulation widgets for web applications. The library contains a vulnerability that allows attackers to execute arbitrary JavaScript code in a user's browser if the user copies content from a malicious source and pastes it into the HTML editor component. This could lead to session hijacking, credential theft, or malware distribution.
Technical details
jsuites contains a DOM-based cross-site scripting (XSS) vulnerability in its HTML editor component due to improper sanitization of clipboard content. When a user pastes data into the editor, part of the clipboard content is directly written to innerHTML without neutralizing HTML/JavaScript payload, allowing an attacker to inject malicious scripts. The attack requires user interaction (copying from a malicious source and pasting into the editor), but has a low barrier to social engineering. The vulnerability affects all versions prior to 4.9.11, which contains a fix that sanitizes clipboard input before DOM insertion.
Affected products
- jsuites jsuites < 4.9.11
Timeline
- 2021-09-21: disclosed: Advisory published on GitHub
- 2021-09-21: patched: Fix available in version 4.9.11