Vulnerability library
Security checkFebruary 22, 2023

Cross-Site-Scripting attack on `<RichTextField>` - react-admin

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmreact-admin

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

All React applications built with react-admin and using the <RichTextField> are affected.

<RichTextField> outputs the field value using dangerouslySetInnerHTML without client-side sanitization. If the data isn’t sanitized server-side, this opens a possible Cross-Site-Scripting (XSS) attack.

Recommendation

Update the react-admin package to the latest compatible version. Followings are version details:

  • Affected version(s): **>= 4.0.0, < 4.7.6 < 3.19.12**
  • Patched version(s): **4.7.6 3.19.12**

References

Could your website be exposed too?

SmartScanner can check your website for Cross-Site-Scripting attack on `<RichTextField>` - react-admin and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated February 22, 2023