[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] Re: CVE Request: Anchor CMS - Multiple Stored and DOM Based XSS issues
From:       Anirudh Anand <anirudhanand722 () gmail ! com>
Date:       2015-06-26 19:28:47
Message-ID: CAMntfF3xsdLJ9GHbJHDczaS_6jVDZLDM=yu0G-P4bPsgB3vU3g () mail ! gmail ! com
[Download RAW message or body]


Adding Further details regarding the issue: (sorry for not including the
details in the first mail).

1)
*Stored/Persistent XSS: *
While creating a new page (any authenticated user can create a new page),
the page title is not properly sanitized before saving the input the
database and hence users inject their own payloads. A sample POC can be
trying to give the following payload while adding a new page:

Page title = *page"onmouseover="alert(1)";*

Same injection can be also done on username field while creating a new user
or when editing an already existing user. So any user can purposefully add
JavaScript along with his name. If the user profile page is visited by the
admin or any other users, it will trigger the JavaScript.

2) *DOM Based XSS:*

DOM Based XSS occurs under every single URL below* /admin/*. A sample POC
can be:

http://localhost/anchor-cms/admin/posts/%3Cscript%3Ealert%281%29%3C/script%3E
 <http://localhost/anchor-cms/admin/%3Cscript%3Ealert%281%29%3C/script%3E>
ttp://localhost/anchor-cms/admin/%3Cscript%3Ealert%281%29%3C/script%3E
<http://localhost/anchor-cms/admin/%3Cscript%3Ealert%281%29%3C/script%3E>


*Date of reporting:* 24th June, 2015

*Exploit Author:* Anirudh Anand

*Vendor Homepage*: https://anchorcms.com

*Software Link:* http://anchorcms.com/download

*Version: *< 0.9.2

*Tested on:* Linux:- Ubuntu, Debian


The issue has been reported to the vendor:
https://github.com/anchorcms/anchor-cms/issues/876

Is it possible to assign CVE identifiers for the same ?

Thank you,

On Thu, Jun 25, 2015 at 4:53 PM, Anirudh Anand <anirudhanand722@gmail.com>
wrote:

> Hello,
>
> I would like to receive CVE identifier for the following Issues in the
> latest version of Anchor CMS:
>
> *Reference: *
> https://github.com/anchorcms/anchor-cms/issues/876
>
> Anchor CMS is a very popular content Management System. There are multiple
> Stored and DOM based XSS issues in it as reported in the reference. These
> issues persists in all the latest Anchor CMS releases.
> --
>
> Anirudh Anand
> bi0s@AMRITA
> www.securethelock.com
>
> *"Those who Say it cannot be done, should not interrupt the people doing
> it"*
>



-- 

Anirudh Anand
bi0s@AMRITA
www.securethelock.com

*"Those who Say it cannot be done, should not interrupt the people doing
it"*


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic