PT-2026-98242 · Unknown · Code16/Sharp
CVE-2026-61823
·
Published
2026-09-24
·
Updated
2026-09-25
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
code16 Sharp versions prior to 9.22.5
Description
A stored cross-site scripting issue exists in the rich-text editor because the HTML sanitizer allows the
srcdoc attribute on iframe elements. While markup within srcdoc is HTML-encoded during sanitization, browsers decode these entities before interpreting the iframe document. This allows an authenticated user with permissions to edit an Editor field to store executable JavaScript that executes when another user views the content. This can lead to session hijacking, unauthorized actions, account takeover, privilege escalation, or disclosure of administrative data.Recommendations
Update to version 9.22.5.
As a temporary workaround, manually sanitize all Editor field content and remove every iframe
srcdoc attribute before storing or rendering it.Exploit
Fix
LPE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Code16/Sharp