CVE-2021-4103: Cross-site Scripting (XSS) - Stored in vanessa219/vditor
Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 1.0.34.
Other sources
vditor does not filter user input in SVG events, leading to XSS
PoC
html </a> <svg><animate onbegin=alert(11) attributeName=x dur=1s>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-4103?
CVE-2021-4103 is categorized as a high severity vulnerability due to its potential for exploiting stored cross-site scripting (XSS) in affected applications.
How do I fix CVE-2021-4103?
To fix CVE-2021-4103, upgrade to Vditor version 1.0.34 or later, which includes patches for the XSS vulnerability.
What is the impact of exploiting CVE-2021-4103?
Exploiting CVE-2021-4103 allows an attacker to execute arbitrary JavaScript code in the context of a user's session, potentially leading to data theft or account compromise.
Which versions are affected by CVE-2021-4103?
CVE-2021-4103 affects all versions of Vditor prior to 1.0.34.
Who is affected by CVE-2021-4103?
Any user or organization using Vditor versions before 1.0.34 is at risk of being affected by CVE-2021-4103.