Executive brief
Webiny, an open-source content management system (CMS), contains a vulnerability in how it displays rich text content. A content manager with administrative access could insert malicious scripts into the CMS that would then execute in the browsers of other users or administrators when they view the affected pages. This could lead to unauthorized actions being performed in the context of the victim's session.
Technical details
The @webiny/react-rich-text-renderer package, used to render data from Webiny Headless CMS and Form Builder, is vulnerable to stored Cross-Site Scripting (XSS). The component relies on editor.js for rich text handling and renders the resulting content using the React 'dangerouslySetInnerHTML' prop without prior HTML sanitization. An attacker with content manager privileges (PR:H) can inject malicious scripts into the CMS database. These scripts execute in the security context of any user (including administrators) who subsequently views the rendered content. The vulnerability affects projects created prior to version 5.35.0 using the legacy editor.js-based renderer and is fixed in version 5.37.2 by implementing proper HTML sanitization.
Affected products
- Webiny @webiny/react-rich-text-renderer <= 5.37.1
Timeline
- 2023-08-23: patched: Fix committed to webiny-js repository
- 2023-08-24: disclosed: Security advisory published on GitHub
- 2023-08-25: advisory: NVD record published