CyberRota Analysis
AI-GeneratedThe vulnerability affects versions of the Laravel-based code16 Sharp framework prior to 9.22.5, specifically in its rich-text editor, which allows for stored cross-site scripting through the `srcdoc` attribute on iframe elements. This flaw can lead to severe impacts such as session hijacking, account takeover, and unauthorized actions when exploited by authenticated users with editing permissions. Organizations using affected versions should prioritize upgrading to 9.22.5 or implement manual sanitization of iframe content to mitigate the risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in the rich-text editor because the HTML sanitizer permits the `srcdoc` attribute on iframe elements. Although markup inside `srcdoc` is HTML-encoded during sanitization, browsers decode attribute entities before interpreting the iframe document, allowing an authenticated user with permission to edit an Editor field to store executable JavaScript that runs when another user views the content. Successful exploitation can result in session hijacking, unauthorized actions, account takeover, privilege escalation, or disclosure of administrative data. Version 9.22.5 patches the vulnerability by removing `srcdoc` from the permitted iframe attributes. As a workaround, applications that cannot upgrade should manually sanitize all Editor field content and remove every iframe `srcdoc` attribute before storing or rendering it.