Lucene search

K
huntrP0cas25775287-88CD-4F00-B978-692D627DFF04
HistoryDec 08, 2021 - 7:21 a.m.

Cross-site Scripting (XSS) - Reflected in gnuboard/gnuboard5

2021-12-0807:21:19
p0cas
www.huntr.dev
36

0.001 Low

EPSS

Percentile

30.0%

Description

The reflected XSS vulnerability occurs to a flaw in the clean_xss_tags() function called in memo.php of Gnuboard 5. This clean_xss_tags() is a Sanitizer that removes XSS-vulnerable tags and attributes. However, it can bypass Sanitizer by using a newline character. (%0A, %0D, ETC)

Proof of Concept

1. Open the https://sir.kr/bbs/memo.php?kind=%0D%3C/noscript%3E%3Csvg/onload=alert(document.domain)%3E&spam=1
2. you can see that occur a xss after login

Impact

Through this vulnerability, an attacker is capable to execute malicious scripts.

0.001 Low

EPSS

Percentile

30.0%

Related for 25775287-88CD-4F00-B978-692D627DFF04