Impact
The sanitizer in SunEditor does not reject namespaced or custom HTML elements, so event‑handler attributes survive on crafted elements. When an application renders attacker‑controlled editor content, a user interaction triggers the retained handler and executes arbitrary script in the page’s browser origin. This allows an attacker to read or modify data, inject malicious content, or perform unauthorized actions within the application context, causing significant confidentiality, integrity, and availability impact.
Affected Systems
This flaw affects the SunEditor library supplied by JiHong88. All releases prior to version 2.47.11 are vulnerable. Applications that embed these older editor versions and trust user‑generated content are at risk.
Risk and Exploitability
The product has a CVSS score of 10, indicating maximum severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Attack requires that the application render compromised editor content and that an end‑user interact with the malicious element. Because the flaw is a stored XSS that executes in the victim’s browser session, it can be amplified by social engineering or malicious user uploads. The risk is high, especially for user‑facing applications or content management systems that rely on SunEditor.
OpenCVE Enrichment