Executive brief
Vditor is a Markdown editor component used in web applications. The editor fails to properly sanitize anchor element attributes during preview rendering, allowing attackers to inject malicious JavaScript that executes in users' browsers when they view specially crafted content. This can lead to session hijacking, credential theft, or malware distribution to application users.
Technical details
Vditor 3.10.3 contains a Cross-site Scripting (CWE-79) vulnerability in the preview functionality where user-supplied content within HTML anchor element attributes is not adequately sanitized before rendering. An attacker can inject malicious scripts via attributes of an `A` element in Markdown input that will execute in the victim's browser context. The vulnerability affects the default configuration; however, the vendor notes that enabling the `sanitize=true` option can mitigate the issue. No information regarding patch availability or the affected version range beyond 3.10.3 is currently documented.
Affected products
- Vanessa219 Vditor 3.10.3 and earlier
Timeline
- 2024-05-03: disclosed