summernote / summernote

Super simple WYSIWYG editor
https://summernote.org
MIT License
11.4k stars 2.24k forks source link

XSS Vulnerability Report: Discovering XSS Vulnerability through Data Schema Manipulation #4638

Open EunhoKim98 opened 3 weeks ago

EunhoKim98 commented 3 weeks ago

Checklist

Steps to reproduce

Step1. Click on the "Insert Image" button within the Summernote functionality.

1

Step2. Select an arbitrary image and insert it.

2

3

Step3. Click on the "Code View" button.

4

Step4. Attempt an XSS attack by manipulating the code of the inserted image.