Executive brief
Jodit Editor is a popular JavaScript-based rich text editor component used in web applications to allow users to create and edit formatted content. An attacker can inject malicious JavaScript code through the editor's content, which executes in the browsers of anyone viewing that content, potentially stealing session cookies, stealing sensitive information, or performing actions on behalf of the victim.
Technical details
The vulnerability is a Stored/Reflected XSS (CWE-79) in Jodit Editor's rich text editor component that fails to properly sanitize or filter user input. The editor does not completely remove malicious XSS payloads such as `<iframe src="JavaScript: alert (/xss/)">`, allowing attackers to inject arbitrary JavaScript that executes in the context of the application. The attack requires user interaction (opening or viewing the malicious content) but does not require authentication or special network conditions. An attacker can obtain sensitive information through this vulnerability and potentially execute arbitrary actions in the context of the web application.
Affected products
- xdsoft Jodit Editor 4.0.0-beta.86 and earlier 4.x versions
Timeline
- 2023-09-19: disclosed: Vulnerability published in GitHub Security Advisory
- 2023-09-18: other: Issue reported on GitHub