Skip to content

Latest commit

 

History

History
21 lines (13 loc) · 1.14 KB

html-injection-page-content-blockquote-author-v0.13.1.md

File metadata and controls

21 lines (13 loc) · 1.14 KB

HTML Injection in Author for a Blokquote in enhavo 0.13.1

Software link: Enhavo 0.13.1 [https://www.enhavo.com]

@author: Daniel Puente

@description: HTML Injection vulnerability in the field Author from the panel new Page -> Content-> Blockquote, of Enhavo v0.13.1 allow attackers to deface the webpage HTML via a crafted payload injected into Author field.


PoC

  1. A page is added or is just edited, when editing its content, we need to create a new blockquote, where a crafted payload is given in the Àuthor field. image image

  2. As a result, when saved and previewed, the HTML Injection becomes visible. image

  3. If accessed without the need of login (at the time of writing - 11/03/2023 - is published in [https://demo.enhavo.com/14]) it will be shown. image