ProseMirror 的视图组件负责渲染和管理 ProseMirror 文档的可编辑浏览器界面。在 1.42.3 版本之前,prosemirror-view 的粘贴处理功能会接受攻击者提供的 HTML 内容,其中剪贴板切片上下文包含的某些属性未通过 schema 属性验证。当用户将精心构造的 HTML 粘贴到编辑器中时,这些未经校验的上下文属性可能生成包含攻击者控制的 JavaScript 代码的内容,从而在包含编辑器的浏览器窗口中执行恶意脚本。该问题已在 1.42.3 版本中得到修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ProseMirror | prosemirror-view | < 1.42.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ProseMirror | prosemirror-view | < 1.42.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet