Junglewise Threat Intelligence

CVE-2022-27103: element-plus cross-site scripting in el-table-column

CVE-2022-27103 · Severity: low · CVSS 3.1 · Published 2022-04-26

Vendors: npm.

Executive brief

element-plus is a popular Vue.js component library used to build web applications. The library's table component has a feature that displays tooltip text when hovering over table cells; when this feature is enabled, the library fails to properly sanitize user-supplied content, allowing an attacker to inject malicious scripts. If a web application displays user-controlled data in such tooltips, the attacker's scripts execute in the context of the victim's browser session, potentially enabling account compromise or data theft.

Technical details

The vulnerability is a classic reflected cross-site scripting (XSS) flaw in the el-table-column component. When the show-overflow-tooltips attribute is set to true, the render-helper module renders tooltip text as raw HTML without proper sanitization or escaping. An attacker can inject HTML/JavaScript payloads into table cell content; upon mouseover, these payloads are interpreted as code rather than plain text. The vulnerability requires user interaction (hovering over the affected cell) and affects versions below 2.0.6. A patch was released in version 2.0.6 via commit 063c564.

Affected products

  • element-plus element-plus below 2.0.6

Timeline

  • 2022-04-26: disclosed
  • 2022-04-26: patched: Fixed in version 2.0.6

References

Related threats