CVE-2023-27472 HIGH

CVE-2023-27472: HTML tags in entity names in the tree view are not sanitised in quickentity-editor-next

Vendor Atampy25
Product quickentity-editor-next
Weakness CWE-79 · XSS
Published March 6, 2023
Last update February 25, 2025

CVSS base score

8.2/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

What the vulnerability does

01Description

quickentity-editor-next is an open source, system local, video game asset editor. In affected versions HTML tags in entity names are not sanitised (XSS vulnerability). Allows arbitrary code execution within the browser sandbox, among other things, simply from loading a file containing a script tag in any entity name. This issue has been patched in version 1.28.1 of the application. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Key dates

02Disclosure timeline

March 6, 2023 CVE published
February 25, 2025 Record updated