Vulnerability GHSA-qxg3-46rw-79j8
Summary
code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute
Details
Impact
A Stored Cross-Site Scripting (XSS) vulnerability exists in the rich text editor due to improper sanitization of the srcdoc attribute on elements.</p> <p>While the underlying Symfony HtmlSanitizer correctly HTML-encodes special characters inside the attribute value (e.g., converting <script> to <script>), the HTML specification mandates that browsers automatically decode HTML entities inside attribute values before processing them. As a result, any encoded JavaScript inside a srcdoc attribute is evaluated and executed as live HTML/JS in the context of the iframe when the page is rendered.</p> <p>An attacker with permissions to edit an Editor field can inject malicious scripts to target other users viewing the content. Potential impacts include:</p> <ul> <li>Session Hijacking (stealing admin session cookies via document.cookie)</li> <li>Account Takeover & Privilege Escalation (e.g., a low-privileged editor triggering actions as an Administrator)</li> <li>Admin panel data theft</li> </ul> <h3>Patches</h3> <p>The vulnerability has been patched in version v9.22.5.</p> <p>The fix explicitly removes srcdoc from the list of allowed iframe attributes in <code>src/Utils/Sanitization/FormatsSanitizedValue.php</code>.</p> <h3>Workarounds</h3> <p>Users who cannot upgrade immediately can manually sanitize all content of editor fields to strip <code>srcdoc</code> attributes.</p>
Related Vulnerabilities
Other vulnerabilities affecting the same packages