PT-2023-12187 · Vditor · Vditor

·

CVE-2021-32855

·

Published

2023-02-20

·

Updated

2023-03-02

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Vditor versions prior to 3.8.7
Description Vditor is a browser-side Markdown editor. The issue at hand is a copy-paste cross-site scripting (XSS) problem. For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor.
Recommendations For versions prior to 3.8.7, update to version 3.8.7 to resolve the issue. As a temporary workaround, consider restricting the use of the text editor until the patch is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32855
GHSA-VFMP-9999-6WQJ

Affected Products

Vditor