CVE-2022-25038
Description
wanEditor v4.7.11 was discovered to contain a cross-site scripting (XSS) vulnerability via the video upload function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
WangEditor v4.7.11 has a stored XSS vulnerability in its video upload function, allowing arbitrary script execution.
Vulnerability
Overview
WangEditor v4.7.11, a web-based rich text editor, is affected by a cross-site scripting (XSS) vulnerability through its video upload feature. The root cause lies in insufficient sanitization of user-supplied input when inserting video content, enabling an attacker to inject malicious HTML or JavaScript code [1].
Exploitation
Prerequisites
Exploitation requires an authenticated user (or any user with access to the editor) to insert a crafted video payload. The provided proof-of-concept demonstrates that an attacker can inject an ` element with a srcdoc attribute containing a JavaScript payload (e.g., `) to trigger the XSS upon rendering [1]. No special network position is required—the attack can be carried out from a browser.
Impact
Successful exploitation enables an attacker to execute arbitrary JavaScript in the context of the victim's browser session. This can lead to data theft, session hijacking, or defacement of pages that include the editor output. The vulnerability is classified as medium severity (CVSS 6.1) due to the requirement for user interaction and the non-direct access to sensitive systems [1].
Mitigation and
Status
As of the publication date (2024-05-31), no patched version had been released. Users are advised to apply input sanitization on the server side or restrict the use of the video upload feature until an update is available. The vulnerability has been publicly disclosed with a working exploit, increasing the risk of active exploitation [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: =4.7.11
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.