Vanilla Forums 2.0.18.4 Tagging Enhanced 1.0.1 Stored Cross Site Scripting

2012.06.04
Credit: Henry Hoggard
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

# Title: Vanilla Tagging Enchanced 1.0.1 Stored XSS # Date: 1/6/12 # Author: Henry Hoggard # Author URL: henryhoggard.co.uk # Author Twitter: @henryhoggard # Software: Vanilla Version 2.0.18.4 + Tagging Enhanced plugin 1.0.1 # http://vanillaforums.org/download # http://vanillaforums.org/addon/tagging-plugin This plugin is based on the default tagging plugin that comes with Vanilla. Therefore this is vulnerable to the same attack. Create a new thread and post your XSS as tag. I used <script>alert('xss')</script> You will have to use a proxy / manipulate the form to bypass the max-length on the form. Once you have posted the thread, send an administrator or moderator to http://target.tld/index.php?p=/vanilla/post/editdiscussion/7 Where 7 is the thread ID of the thread you just made. The XSS will then trigger. You can even use a URL shortener to send the link. Note: The URL may be different depending on what category your thread is in. #############################################################

References:

http://vanillaforums.org/download


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top