CVE-2024-53847

CVSS

No CVSS.

T

he Trix rich text editor, prior to versions 2.1.9 and 1.3.3, is vulnerable to cross-site scripting (XSS) + mutation XSS attacks when pasting malicious code. An attacker could trick a user to copy and paste malicious code that would execute arbitrary JavaScript code within the context of the user's session, potentially leading to unauthorized actions being performed or sensitive information being disclosed. Users should upgrade to Trix editor version 2.1.9 or 1.3.3, which uses DOMPurify to sanitize the pasted content.

Configurations

No configuration.

History

09 Dec 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-09 19:15

Updated : 2024-12-09 19:15


NVD link : CVE-2024-53847

Mitre link : CVE-2024-53847

CVE.ORG link : CVE-2024-53847


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')