GHSA-fxwm-rx68-p5vx

    Dashboard / Vulnerabilities / GHSA-fxwm-rx68-p5vx

    GHSA-fxwm-rx68-p5vx

    Published: 1 Dec 2021Last Modified: 29 Nov 2024

    Summary: XSS in richtext custom tag attributes in ezsystems/ezplatform-richtext

    Details: The rich text editor does not escape attribute data when previewing custom tags. This means XSS is possible if custom tags are used, for users who have access to editing rich text content. Frontend content view is not affected, but the vulnerability could be used by editors to attack other editors. The fix ensures custom tag attribute data is escaped in the editor.

    Affected packages

    Package

    Name: ezsystems/ezplatform-richtext

    Purl: pkg:composer/ezsystems/ezplatform-richtext

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 2.3.0
    Fixed -2.3.7.1

    Affected versions

    v2.3.0
    v2.3.1
    v2.3.2
    v2.3.3
    v2.3.4
    v2.3.5
    v2.3.6
    v2.3.7

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-fxwm-rx68-p5vx | CVE-DB