Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

GHSA-xv83-x443-7rmw: HTML injection in search results via plaintext message highlighting

### Impact Plain text messages containing HTML tags are rendered as HTML in the search results. To exploit this, an attacker needs to trick a user into searching for a specific message containing an HTML injection payload. No cross-site scripting attack is possible due to the hardcoded content security policy. ### Patches Version 3.71.0 of the SDK patches over the issue. ### Workarounds Restarting the client will clear the HTML injection.

ghsa
#xss#nodejs#git
GHSA-fh7r-996q-gvcp: Possible XSS injection through Validate::isCleanHTML method

### Impact ValidateCore::isCleanHTML() method of Prestashop misses hijickable events which can lead to XSS injection, allowed by the presence of pre-setup @keyframes methods. This XSS which hijacks HTML attributes will be triggered without any interaction of the visitor/administrator which makes it as dangerous as a trivial XSS. Contrary to most XSS which target HTML attributes and which are triggered without user interaction (such as onload / onerror which suffer from a very limited scope), this one can hijack every HTML element, which increases the danger due to a complete HTML elements scope. ### Patches The patch will be on PS 8.0.4 and PS 1.7.8.9 ### References

CVE-2021-44461: [SEC] CVE-2021-44461 - Cross-site scripting (XSS) issue in Accountin... · Issue #107686 · odoo/odoo

Cross-site scripting (XSS) issue in Accounting app of Odoo Enterprise 13.0 through 15.0, allows remote attackers who are able to control the contents of accounting journal entries to inject arbitrary web script in the browser of a victim.

CVE-2023-30838: Merge pull request from GHSA-fh7r-996q-gvcp · PrestaShop/PrestaShop@dc68219

PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, the `ValidateCore::isCleanHTML()` method of Prestashop misses hijackable events which can lead to cross-site scripting (XSS) injection, allowed by the presence of pre-setup `@keyframes` methods. This XSS, which hijacks HTML attributes, can be triggered without any interaction by the visitor/administrator, which makes it as dangerous as a trivial XSS attack. Contrary to other attacks which target HTML attributes and are triggered without user interaction (such as onload / onerror which suffer from a very limited scope), this one can hijack every HTML element, which increases the danger due to a complete HTML elements scope. Versions 8.0.4 and 1.7.8.9 contain a fix for this issue.

CVE-2023-25793: WordPress Link Juice Keeper plugin <= 2.0.2 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in George Pattihis Link Juice Keeper plugin <= 2.0.2 versions.

CVE-2023-25485: WordPress JSON Content Importer plugin <= 1.3.15 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bernhard Kux JSON Content Importer plugin <= 1.3.15 versions.

CVE-2021-26947: [SEC] CVE-2021-26947 - Cross-site scripting (XSS) issue Odoo Communi... · Issue #107694 · odoo/odoo

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via a crafted link.

CVE-2021-44775: [SEC] CVE-2021-44775 - Cross-site scripting (XSS) issue in Website a... · Issue #107691 · odoo/odoo

Cross-site scripting (XSS) issue in Website app of Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, by posting crafted contents.

CVE-2021-26263: [SEC] CVE-2021-26263 - Cross-site scripting (XSS) issue in Discuss a... · Issue #107693 · odoo/odoo

Cross-site scripting (XSS) issue in Discuss app of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to inject arbitrary web script in the browser of a victim, by posting crafted contents.

CVE-2021-45071: [SEC] CVE-2021-45071 - Cross-site scripting (XSS) issue Odoo Communi... · Issue #107697 · odoo/odoo

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via crafted uploaded file names.