Intel

AIKIDO-2024-10080

trix is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2024-34341 Published May 3, 2024

50

Medium Risk

This Affects:

JStrix
0.9.0 - 1.3.1
Fixed in 1.3.2
2.0.0 - 2.1.0
Fixed in 2.1.1
Are you affected? Scan for Free

TL;DR

Affected versions of the trix library are vulnerable to Cross-site Scripting (XSS) when a specially crafted HTML, including the noscript tag, is copied and pasted.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

trix is vulnerable to Cross-site Scripting (XSS) in versions 0.9.0 - 1.3.1 and 2.0.0 - 2.1.0.

How to fix this

Upgrade the trix library to the patch version.