Editor.js is a block-style editor with clean JSON output. Versions prior to 2.26.0 are vulnerable to Code Injection via pasted input. The processHTML method passes pasted input into wrapper’s innerHTML. This issue is patched in version 2.26.0.
References
Link Resource
https://github.com/codex-team/editor.js/pull/2100 Exploit Patch Third Party Advisory
https://securitylab.github.com/advisories/GHSL-2022-028_codex-team_editor_js/ Exploit Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-12-15T02:08:07.054Z

Updated:

Reserved: 2022-01-19T21:23:53.757Z


Link: CVE-2022-23474

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-12-15T19:15:16.613

Modified: 2022-12-20T01:56:18.700


Link: CVE-2022-23474

JSON object: View

cve-icon Redhat Information

No data.