Invision Power Board <= 3.4.1 persistent XSS (About me)

2013.03.04
Credit: Infern0_
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

# Author: Infern0_ # Contact: balut2@o2.pl # Vendor: http://www.invisionpower.com # Vulnerability: Persistent XSS # Vendor informated at: 5 February 2013 # Solution: Disable possibility to use HTML in posts - in administrator panel. Default disabled in v.3.4.2 of IP.B IP.B v3.4.1 is already a stable version of this software. To reproduce this issue follow this steps(Obviously you have to be logged in): 1.Go to "My profile settings" 2.Find "Informations about profile" and button "Edit site 'About me'" 3. In that text area paste this code :"<body onload=alert(document.cookie)>" (DOM based xss, and <script></script> works as well. There isn't any code sanitization, so you can enter here everything you want to). Click : "Save". 4. Now go to your profile review(Again choose 'My profile') and here it is - persistent XSS disclosed.

References:

http://www.invisionpower.com


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top