Coordinated Disclosure Timeline
Copy-paste XSS in textAngular text editor
Issue: Copy-paste XSS in textAngular (
The textAngular text editor is vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor.
Proof of concept (tested on Chrome):
- Open this page: cdn.sekurak.pl/copy-paste/playground.html
- Paste the following code into “HTML Input”
<div class="MsoNormal">foobar<img src="foo" onload="alert(1)" onerror="alert(2)"/></div>
- Click “Copy as HTML”
- Open http://textangular.com
- Paste into the text editor.
This issue may lead to XSS with user interaction
You can contact the GHSL team at
email@example.com, please include a reference to
GHSL-2021-1001 in any communication regarding this issue.