Coordinated Disclosure Timeline
- 2021-09-15: Report sent to email@example.com
- 2021-09-17: Emails get bounced back. Request contact publicly
- 2021-09-21: Report sent to firstname.lastname@example.org
- 2021-09-22: Issue collision with a different security researcher
- 2021-09-22: Issues fixed in 1b2382d
Copy-paste XSS in vditor text editor
Issue: Copy-paste XSS in vditor (
The vditor text editor is vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor.
Proof of concept (tested on Chrome):
- Open this page: cdn.sekurak.pl/copy-paste/playground.html
- Paste the following code into “HTML Input”
<img src="foo" onload="alert(1)" onerror="alert(2)"/>
- Click “Copy as HTML”
- Open https://b3log.org/vditor/demo/option-mode.html
- Paste into the text editor.
This issue may lead to XSS with user interaction
You can contact the GHSL team at
email@example.com, please include a reference to
GHSL-2021-1006 in any communication regarding this issue.