Connect with us
X
Categories:

Technology

A trio of XSS flaws in open source web applications might jeopardize the entire system

Published

on

A trio of XSS flaws in open source web applications might jeopardize the entire system
Share this post:

Researchers have released details on a trio of cross-site scripting (XSS) vulnerabilities in popular open source apps that could lead to remote code execution (RCE).

The security bugs, found by a research team from PT Swarm, were discovered in web development applications Evolution CMS, FUDForum, and GitBucket.

A traditional XSS attack allows the attacker’s JavaScript code to be executed in the victim user’s browser, opening the door to cookie theft, redirection to a phishing site, and much more.

Web security researcher Aleksey Solovev told The Daily Swig that this research, detailed in PT Swarm’s blog, relates to how “the combination of the discovered possibility of conducting an XSS attack and the built-in file manager (or executing a SQL query) in the administrator panel can lead to a complete compromise of the system”.

Triple threat

The first vulnerability, in Evolution CMS v3.1.8, could allow an attacker to carry out a reflected XSS attack in several places in the admin panel.

“An attacker could try to force a system administrator to follow a malicious link through social engineering, which would lead to the execution of malicious JavaScript code in the browser of the attacked,” Solovev told Daily Swig.

“The consequence would be a complete compromise of the system by overwriting the executable file using the built-in file manager.”

A second flaw, found in FUDforum v3.1.1, could potentially allow a malicious actor to carry out a stored XSS attack in the name of the attached file in private messages.

“An attacker could send a private message to an administrator with a malicious payload in the name of the attached file,” said Solovev.

“When this message is read by the administrator, his browser would execute the JavaScript code and, using the built-in file manager, an executable file would be created that would allow the attacker to execute commands on the server.”

Finally, in GitBucket v4.37.1, a security bug was discovered that could enable an attacker to carry out a stored XSS attack in “several places”, according to Solovev.

An attacker had to create an issue in a public repository and inject a JavaScript code into the name of the assignment.

RECOMMENDED  Your daily horoscope for Friday, September 2, 2022

This event would be displayed in the general feed and the attacker’s profile. It was in these places that the insecure display of the task name with a malicious load was present, which led to the execution of JavaScript code in the browser of everyone who viewed these pages.

“In the admin panel, it was possible to execute SQL code based on the H2 Database Engine, for which there is already an exploit that allows you to execute a command on the server,” Solovev explained.

“Putting everything together, an attacker could attack the administrator and gain the ability to execute commands on the server.”

Patches released

All three vulnerabilities are pending a CVE but have been patched by the maintainers of the projects, Solovev told The Daily Swig.

The researcher added that the main difficulty in discovering these flaws was to find the possibility of conducting an XSS attack.

“The rest of the steps were easier because they had public exploits for legitimate functionality in the form of a file manager in the admin panel,” he explained.

More information about the vulnerabilities and technical detail on the exploit can be found in PT Swarm’s blog.


Get More Stories Like This On: Facebook: @AllNaijaEntertainment, Twitter: @AllNaijaEntertainment
General4 hours ago

Skylar Grey – Everything I Need [LYRICS]

General4 hours ago

[Music] Diddy – Dirty Money – “Coming Home” Feat. Skylar Grey

General4 hours ago

Diddy – Dirty Money – “Coming Home” Feat. Skylar Grey [LYRICS]

General4 hours ago

[Music] African China – Amen

General4 hours ago

[Music] African China – Baba God

General4 hours ago

African China – Baba God [LYRICS]

General4 hours ago

Machine Gun Kelly (MGK) “Home” Feat X Ambassadors & Bebe Rexha [LYRICS]

General5 hours ago

Passenger – Let Her Go [LYRICS]

General5 hours ago

[Music] Eminem – “No Love” Feat. Lil Wayne

General5 hours ago

Eminem – “No Love” Feat. Lil Wayne [LYRICS]

Music5 hours ago

[Music] Tatiana Manaois – Buzz Kill

General5 hours ago

Tatiana Manaois – Buzz Kill [LYRICS]

General5 hours ago

James Blunt – Goodbye My Lover [LYRICS]

General5 hours ago

Major Lazer – “Particula” Feat. Nasty C , Ice Prince, Patoranking & Jidenna [LYRICS]

General5 hours ago

James Blunt – You’re Beautiful [LYRICS]

General5 hours ago

Justin Timberlake – Mirrors [LYRICS]

General5 hours ago

[Music] Darey – “Pray For Me” feat. Soweto Gospel Choir

General5 hours ago

Eminem – “Love The Way You Lie” Feat. Rihanna [LYRICS]

General5 hours ago

Goldlink ft. Miguel – Got Friends [LYRICS]

General5 hours ago

Sia – I’m Still Here [LYRICS]

General5 hours ago

Yo Gotti ft. Nicki Minaj – Rake It Up [LYRICS]

General5 hours ago

Shane McMahon – Here Comes The Money [LYRICS]

General6 hours ago

Journey – Faithfully [LYRICS]

General6 hours ago

[Music] Journey – Faithfully

General6 hours ago

Eminem – Not Afraid [LYRICS]

General6 hours ago

[Music] Journey – Don’t Stop Believin’

General6 hours ago

Journey – Don’t Stop Believin’ [LYRICS]

General6 hours ago

21 Savage – Bank Account [LYRICS]

General6 hours ago

Demi Lovato – Sober [LYRICS]

General7 hours ago

Beyonce ft. Jay-Z – Apeshit [LYRICS]

General7 hours ago

Nasty C ft. ASAP Ferg – King [LYRICS]

General7 hours ago

Lil Wayne – Uproar [LYRICS]

Ed Sheeran
Lyrics7 hours ago

Ed Sheeran – Perfect [LYRICS]

General7 hours ago

[Music] Mo’Hits All Star – Close To You

General7 hours ago

Lil Dicky ft. Chris Brown – Freaky Friday [LYRICS]

Michael Jackson
Lyrics7 hours ago

Michael Jackson – Stranger In Moscow [LYRICS]

General7 hours ago

[Music] Celine Dion – I Drove All Night

General7 hours ago

Celine Dion – I Drove All Night [LYRICS]

General7 hours ago

Tatiana Manaois – Hey Little Lady [LYRICS]

Music7 hours ago

[Music] Tatiana Manaois – Live Better

Gnash (singer)
Music4 days ago

[Music] Gnash Ft Olivia O’Brien – I Hate you, I Love you

John Legend
Music1 day ago

[INSTRUMENTAL] John Legend – All Of Me

Alan Walker
Music5 days ago

Alan Walker – Faded [INSTRUMENTAL]

21 Savage
Music2 days ago

[Video] 21 Savage ft. Offset & Metro Boomin – Rap Saved Me

Wiz Khalifa
Music3 days ago

[Instrumental] Wiz Khalifa – See You Again ft. Charlie Puth

General7 days ago

[Music] Sapientdream – Pastlives

Salvation Ministry Choir Amen
Lyrics2 days ago

Salvation Ministry Choir – Amen [LYRICS]

General7 days ago

[Music] Don Omar – Danza Kuduro (feat. Lucenzo)

General5 days ago

[Music] The Chainsmokers – ‘Don’t Let Me Down’ Feat. Daya

General7 days ago

Ladé – Adulthood Anthem (Adulthood Na Scam) [Lyrics]

General7 days ago

[Music] Timbaland – Apologize ft. OneRepublic

Powfu (singer)
Music4 days ago

[Music] Powfu – Death Bed (Coffee for Your Head) Feat. Beabadoobee

General4 days ago

[Music] Wyclef Jean – “Sweetest Girl (Dollar Bill)” Feat. Akon, Lil Wayne, Niia

General3 days ago

[Music] Zayn Malik – Entertainer

Wiz Khalifa - See You Again ft. Charlie Puth
Music4 days ago

[Music] Wiz Khalifa – See You Again ft. Charlie Puth

Music3 days ago

[Music] Exalted Tribe (HICC) – We Dey Halla

Anna Kendrick
Music4 days ago

[Music] Anna Kendrick – Cups (Pitch Perfect’s “When I’m Gone”)

General4 hours ago

[Music] Diddy – Dirty Money – “Coming Home” Feat. Skylar Grey

General1 day ago

[Music] John Legend – Love Me Now

Right Said Fred
Music4 days ago

[Music] Right Said Fred – Stand Up (For the Champions)

Salvation Ministries Mass Choir
Music2 days ago

[Music] Salvation Ministries Choir – Chioma Me Eh(Good God)

General9 hours ago

[Music] Celine Dion – If That’s What It Takes

Salvation Ministries Mass Choir
Lyrics2 days ago

Salvation Ministries Choir – Chioma Me Eh(Good God) [LYRICS]

General10 hours ago

[Music] P!nk – Try

General6 days ago

[Music] Shaggy – Strength Of A Woman

General2 days ago

[Music] Jaden Smith – Goku

Music3 days ago

[Music] Wiz Khalifa – See You Again (Remix) Feat Charlie Puth, Eminem, Tyga, & Chris Brown

R. Kelly
Music4 days ago

[Music] R. Kelly – World’s Greatest

General1 day ago

Magic! — Rude [LYRICS]

General6 hours ago

[Music] Journey – Don’t Stop Believin’

General6 days ago

[Music] Justin Bieber – Love Me

General2 days ago

[Music] Cardi B – Bartier Cardi ft. 21 Savage

General7 days ago

[Music] Lionel Richie – Angel

General3 days ago

[Music] Tyga ft. Offset – Taste

General10 hours ago

[Music] P!nk – “Just Give Me A Reason” Feat. Nate Ruess

General7 days ago

[Music] BIG SHAQ – Man’s Not Hot

General2 days ago

[Music] 21 Savage ft. Offset & Metro Boomin – Rap Saved Me

General7 days ago

[Music] Shayne Ward – Breathless

General6 days ago

[Music] Post Malone – Candy Paint

General5 days ago

[Music] R Kelly – When A Woman Loves

ANE Billboard Hots



Join "ANE sabi" clique

Don't miss a thing, get ogbonge ANE latest updates to fuel your conversation daily.