react-admin is a frontend framework for building browser applications on top of REST/GraphQL APIs. react-admin prior to versions 3.19.12 and 4.7.6, along with ra-ui-materialui prior to 3.19.12 and 4.7.6, are vulnerable to cross-site scripting. All React applications built with react-admin and using the <RichTextField> are affected. <RichTextField> outputs the field value using dangerouslySetInnerHTML without client-side sanitization. If the data isn't sanitized server-side, this opens a possible cross-site scripting (XSS) attack. Versions 3.19.12 and 4.7.6 now use DOMPurify to escape the HTML before outputting it with React and dangerouslySetInnerHTML. Users who already sanitize HTML data server-side do not need to upgrade. As a workaround, users may replace the <RichTextField> by a custom field doing sanitization by hand.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-79"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/25xxx/CVE-2023-25572.json"
}{
"cpe": [
"cpe:2.3:a:marmelab:ra-ui-materialui:*:*:*:*:*:node.js:*:*",
"cpe:2.3:a:marmelab:react-admin:*:*:*:*:*:node.js:*:*"
],
"extracted_events": [
{
"introduced": "4.0.0"
},
{
"fixed": "4.7.6"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}