Intel

AIKIDO-2024-10301

summernote is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2023-42371 Published Sep 30, 2024

51

Medium Risk

This Affects:

jssummernote
0.1.0 - 0.8.20
Fixed in 0.9.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to Cross-site Scripting (XSS) via the createLink function in the Editor class. An attacker can execute arbitrary code by injecting a crafted script.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

summernote is vulnerable to Cross-site Scripting (XSS) in versions 0.1.0 - 0.8.20.

How to fix this

Upgrade the summernote library to the patch version.