Junglewise Threat Intelligence

CVE-2021-42227: KindEditor stored cross-site scripting in file upload

CVE-2021-42227 · Severity: low · CVSS 3.1 · Published 2021-10-18

Vendors: npm.

Executive brief

KindEditor is a popular web-based rich text editor embedded in websites to allow users to create formatted content. The vulnerability allows an attacker to upload malicious HTML files containing JavaScript code, which are then executed in the browsers of users who view or interact with the affected editor, potentially stealing session cookies, performing unauthorized actions on their behalf, or defacing content.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in KindEditor 4.1.x due to insufficient file type validation in the upload handler (upload_json.php). An attacker can bypass file extension restrictions by uploading an HTML file containing embedded JavaScript through the POST /Public/JS/kindeditor-4.1.10/php/upload_json.php endpoint. The uploaded file is stored and served to other users, causing the malicious script to execute in their browsers. The vulnerability requires network access to a website running the vulnerable editor component and can be discovered via search engines indexing the examples directory.

Affected products

  • KindSoft KindEditor 4.1.x, including 4.1.12 and earlier

Timeline

  • 2021-10-14: disclosed: Vulnerability reported on GitHub issue #336
  • 2021-10-18: advisory: GHSA advisory published

References

Related threats