PT-2024-28949 · Unknown · Prosemirror
Rskvp93
·
Published
2024-07-16
·
Updated
2026-01-28
·
CVE-2024-40626
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Outline versions prior to 0.77.3
Description
A type confusion issue in ProseMirror's rendering process leads to a Stored Cross-Site Scripting (XSS) issue. An authenticated user can create a document with a malicious JavaScript payload, which can execute when other users view the document. The issue can bypass Content Security Policy (CSP) restrictions in self-hosted environments with file storage on the same domain.
Recommendations
For versions prior to 0.77.3, upgrade to release version 0.77.3 to address the issue.
Exploit
Fix
DoS
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prosemirror