Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-25572

Опубликовано: 13 фев. 2023
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

react-admin is a frontend framework for building browser applications on top of REST/GraphQL APIs. react-admin prior to versions 3.19.12 and 4.7.6, along with ra-ui-materialui prior to 3.19.12 and 4.7.6, are vulnerable to cross-site scripting. All React applications built with react-admin and using the <RichTextField> are affected. <RichTextField> outputs the field value using dangerouslySetInnerHTML without client-side sanitization. If the data isn't sanitized server-side, this opens a possible cross-site scripting (XSS) attack. Versions 3.19.12 and 4.7.6 now use DOMPurify to escape the HTML before outputting it with React and dangerouslySetInnerHTML. Users who already sanitize HTML data server-side do not need to upgrade. As a workaround, users may replace the <RichTextField> by a custom field doing sanitization by hand.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:marmelab:ra-ui-materialui:*:*:*:*:*:node.js:*:*
Версия до 3.9.12 (исключая)
cpe:2.3:a:marmelab:ra-ui-materialui:*:*:*:*:*:node.js:*:*
Версия от 4.0.0 (включая) до 4.7.6 (исключая)
cpe:2.3:a:marmelab:react-admin:*:*:*:*:*:node.js:*:*
Версия до 3.9.12 (исключая)
cpe:2.3:a:marmelab:react-admin:*:*:*:*:*:node.js:*:*
Версия от 4.0.0 (включая) до 4.7.6 (исключая)

EPSS

Процентиль: 78%
0.01152
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 5.4
github
почти 3 года назад

Cross-Site-Scripting attack on `<RichTextField>`

EPSS

Процентиль: 78%
0.01152
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79