High-Tech Bridge SA Security Research Lab has discovered multiple vulnerabilities in Zikula Application Framework, which can be exploited to perform cross-site scripting attacks.
- Cross-site scripting (XSS) vulnerability in Zikula Application Framework
Input passed via the “themename” parameter to “ztemp/view_compiled/Theme/theme_admin_setasdefault.php” is not properly sanitised before being returned to the user.
This can be exploited to execute arbitrary HTML and script code in a administrator’s browser session in context of affected website.
The following PoC code is available:
http://host/index.php?module=theme&type=admin&func=setasdefault&themename=%3 Cscript%3Ealert%28document.cookie%29%3C/script%3E