Vulnerability library
Security checkAugust 04, 2024

Plate media plugins has a XSS in media embed element when using custom URL parsers

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Editors that use MediaEmbedElement and pass custom urlParsers to the useMediaState hook may be vulnerable to XSS if a custom parser allows javascript:, data: or vbscript: URLs to be embedded. Editors that do not use urlParsers and instead consume the url property directly may also be vulnerable if the URL is not sanitised.

Recommendation

Update the @udecode/plate-media package to the latest compatible version. Followings are version details:

  • Affected version(s): < 36.0.10
  • Patched version(s): 36.0.10

References

Could your website be exposed too?

SmartScanner can check your website for Plate media plugins has a XSS in media embed element when using custom URL parsers and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated August 04, 2024