Executive brief
wangEditor is a popular web-based rich text editor used in websites to allow users to format content. A security flaw in its image upload feature allows an attacker to inject malicious scripts that could execute in the browser of other users. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.
Technical details
A cross-site scripting (XSS) vulnerability exists in wangEditor versions <= 4.7.11 within the image upload functionality. The root cause is insufficient sanitization of user-supplied data during the image handling process. An attacker with low privileges can upload a specially crafted file or payload that, when viewed by another user, executes arbitrary JavaScript in the victim's browser session. This is a stored XSS attack requiring network access and minimal user interaction (viewing the affected content). The issue is resolved in version 4.7.12.
Affected products
- wangeditor-team wangEditor <= 4.7.11
Timeline
- 2024-05-31: disclosed
- 2024-05-31: advisory
References
- https://api.github.com/users/TheeCryptoChad
- https://github.com/TheeCryptoChad
- https://api.github.com/users/TheeCryptoChad/gists%7B/gist_id%7D
- https://api.github.com/users/TheeCryptoChad/repos
- https://avatars.githubusercontent.com/u/54559164?v=4
- https://api.github.com/users/TheeCryptoChad/events%7B/privacy%7D