Intel

AIKIDO-2024-10341

@syncfusion/ej2-documenteditor is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

24

Low Risk

This Affects:

js@syncfusion/ej2-documenteditor
26.2.4 - 27.1.52
Fixed in 27.1.53

TL;DR

Affected versions of the package are vulnerable to Cross-site Scripting (XSS). User input in the comment section of the document editor is potentially not sanitized, allowing attackers to inject malicious scripts that could be executed in the context of other users' browsers.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@syncfusion/ej2-documenteditor is vulnerable to Cross-site Scripting (XSS) in versions 26.2.4 - 27.1.52.

How to fix this

Upgrade the @syncfusion/ej2-documenteditor library to the patch version.