CVE-2023-26149
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
28/09/2023
Last modified:
07/11/2023
Description
Versions of the package quill-mention before 4.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization, via the renderList function. <br />
<br />
**Note:**<br />
<br />
If the mentions list is sourced from unsafe (user-sourced) data, this might allow an injection attack when a Quill user hits @.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:quill-mention:quill_mention:*:*:*:*:*:node.js:*:* | 4.0.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://codepen.io/ALiangLiang/pen/mdQMJXK
- https://github.com/quill-mention/quill-mention/blob/0aa9847719257496b14ac5401872c4e2ffcbc3d1/src/quill.mention.js%23L391
- https://github.com/quill-mention/quill-mention/commit/e85262ddced0a7f0b6fc8350d236a68bd1e28385
- https://github.com/quill-mention/quill-mention/issues/255
- https://github.com/quill-mention/quill-mention/pull/341
- https://security.snyk.io/vuln/SNYK-JS-QUILLMENTION-5921549



