PT-2026-6797 · Sceditor · Sceditor
Sofianeelhor
·
Publicado
2026-02-06
·
Atualizado
2026-02-19
·
CVE-2026-25581
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SCEditor versions prior to 3.2.1
Description
SCEditor is a lightweight WYSIWYG BBCode and XHTML editor. A lack of sanitisation of configuration options passed to the
sceditor.create() function allows an attacker who can control these options—such as emoticons and charset—to trigger a cross-site scripting (XSS) attack. The issue occurs because configuration options are not properly validated, enabling malicious code injection. A proof of concept demonstrates the exploitation using the emoticons option to inject an onerror event handler.Recommendations
Update to version 3.2.1 or later.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sceditor