CVE Database
/

CVE-2024-53847

Back to search

CVE-2024-53847

Published: Dec 9, 2024

Modified: Dec 10, 2024

PUBLISHED

Description

The Trix rich text editor, prior to versions 2.1.9 and 1.3.3, is vulnerable to cross-site scripting (XSS) + mutation XSS attacks when pasting malicious code. An attacker could trick a user to copy and paste malicious code that would execute arbitrary JavaScript code within the context of the user's session, potentially leading to unauthorized actions being performed or sensitive information being disclosed. Users should upgrade to Trix editor version 2.1.9 or 1.3.3, which uses DOMPurify to sanitize the pasted content.

VendorProductVersions

basecamp

trix

affected
>= 2.0.0, < 2.1.9
affected
>= 1.0.0, < 1.3.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now