Executive brief
Toast UI Grid is a JavaScript component for displaying and editing tabular data in web applications. An attacker can inject malicious scripts through specially crafted content pasted into editable cells, potentially allowing them to steal user credentials, session tokens, or perform unauthorized actions on behalf of users viewing the affected page.
Technical details
Toast UI Grid versions prior to 4.21.3 are vulnerable to reflected cross-site scripting (XSS) via CWE-79 when handling pasted content in editable cells. The vulnerability occurs because user-supplied input is not properly sanitized or escaped before being rendered in the DOM. An attacker can craft malicious HTML or JavaScript code and paste it into an editable cell, which is then executed in the browser of any user viewing that data. The attack requires user interaction (pasting content) and can affect multiple users if the malicious data is stored. The fix was released in version 4.21.3.
Affected products
- NHN tui-grid < 4.21.3
Timeline
- 2022-09-23: disclosed
- 2022-09-23: patched: Fixed in version 4.21.3