CVE-2021-32855: GHSL-2021-1006: Copy-paste XSS in vditor text editor - CVE-2021-32855
Copy-paste XSS in vditor text editor
Other sources
Vditor is a browser-side Markdown editor. Versions prior to 3.8.7 are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. Version 3.8.7 contains a patch for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32855?
CVE-2021-32855 has been classified as a medium severity vulnerability due to its potential for exploitation via cross-site scripting.
How do I fix CVE-2021-32855?
To fix CVE-2021-32855, upgrade to Vditor version 3.8.7 or later, which contains the necessary patch.
What type of vulnerability is CVE-2021-32855?
CVE-2021-32855 is a copy-paste cross-site scripting (XSS) vulnerability affecting versions prior to 3.8.7.
What impact does CVE-2021-32855 have on users?
CVE-2021-32855 allows attackers to execute arbitrary scripts in the context of the user's session if they trick the user into pasting a malicious payload.
Which versions of Vditor are affected by CVE-2021-32855?
All versions of Vditor prior to 3.8.7 are affected by CVE-2021-32855.