Junglewise Threat Intelligence

CVE-2023-42399: Jodit Editor cross-site scripting in rich text editor

CVE-2023-42399 · Severity: low · CVSS 3.1 · Published 2023-09-19

Technologies: Xdan Jodit Editor, jodit (npm). Vendors: Xdan, npm.

Executive brief

Jodit Editor is a popular JavaScript-based rich text editor component used in web applications to allow users to create and edit formatted content. An attacker can inject malicious JavaScript code through the editor's content, which executes in the browsers of anyone viewing that content, potentially stealing session cookies, stealing sensitive information, or performing actions on behalf of the victim.

Technical details

The vulnerability is a Stored/Reflected XSS (CWE-79) in Jodit Editor's rich text editor component that fails to properly sanitize or filter user input. The editor does not completely remove malicious XSS payloads such as `<iframe src="JavaScript: alert (/xss/)">`, allowing attackers to inject arbitrary JavaScript that executes in the context of the application. The attack requires user interaction (opening or viewing the malicious content) but does not require authentication or special network conditions. An attacker can obtain sensitive information through this vulnerability and potentially execute arbitrary actions in the context of the web application.

Affected products

  • xdsoft Jodit Editor 4.0.0-beta.86 and earlier 4.x versions

Timeline

  • 2023-09-19: disclosed: Vulnerability published in GitHub Security Advisory
  • 2023-09-18: other: Issue reported on GitHub

References

Related threats