Junglewise Threat Intelligence

CVE-2024-29504: Summernote cross-site scripting in codeview

CVE-2024-29504 · Severity: low · CVSS 3.1 · Published 2024-04-11

Vendors: npm.

Executive brief

Summernote is a widely-used JavaScript library that provides rich text editing capabilities for web applications. A cross-site scripting vulnerability in the codeview feature allows attackers to inject malicious code that executes in users' browsers without proper validation. An attacker could use this to steal session cookies, redirect users to phishing sites, or perform actions on behalf of the victim.

Technical details

This is a classic cross-site scripting (CWE-79) vulnerability in Summernote v0.8.18 and earlier, where user-supplied input to the codeview parameter is not properly sanitized before being rendered in the DOM. The vulnerability has a network attack vector requiring user interaction (clicking a malicious link or visiting a crafted page). An attacker can craft a payload that, when inserted into the codeview, executes arbitrary JavaScript in the context of the vulnerable application. A security fix was developed and submitted via pull request #3782 to the Summernote project. The CVSS score of 6.1 (Medium) reflects the moderate impact of XSS—typically user-scoped account compromise or data exfiltration rather than systemic availability impact.

Affected products

  • Summernote Summernote 0.8.18 and earlier

Timeline

  • 2024-04-11: disclosed
  • 2020-06-15: other: Security fix pull request #3782 submitted

References

Related threats