Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

BBCode URL Tag Script Injection "Shoutbox" PHP Fusion 9.0.36 #2329

Closed
Songohan22 opened this issue May 18, 2020 · 5 comments
Closed

BBCode URL Tag Script Injection "Shoutbox" PHP Fusion 9.0.36 #2329

Songohan22 opened this issue May 18, 2020 · 5 comments

Comments

@Songohan22
Copy link

Songohan22 commented May 18, 2020

Describe the bug
BBCode URL Tag Script Injection "Shoutbox Admin"
To Reproduce
Steps to reproduce the behavior:

  1. Log into the panel.
  2. Go to "/php-fusion/infusions/shoutbox_panel/shoutbox_admin.php"
  3. Click "New Shout"
  4. Insert script injection: [url]https://nvd.nist.gov?[url] onmousemove=javascript:alert(String.fromCharCode(88,83,83));//[/url][/url]
  5. Click " Send Message"
  6. Click "Edit" open url redirect insert script.
    4
  7. Logout user.
  8. Access link "/php-fusion/infusions/shoutbox_panel/shoutbox_archive.php"
  9. Click any "Form Sign In" open url redirect insert script.
    3

Impact
An attacker can use this vulnerability to redirect users to other malicious websites, which can be used for phishing and similar attacks.

Video POC
Video POC link: https://drive.google.com/open?id=1g9x6B-K338qnzHjWtbEHCadpyPLx-daX

Desktop (please complete the following information):

  • OS: Kali
  • Browser: Firefox
  • Version of Browser: 68.6
@RobiNN1
Copy link
Contributor

RobiNN1 commented May 18, 2020

lol you really don't trust your administrators 😂

@Songohan22
Copy link
Author

@RobiNN1
It can be sent from one member.
I will record the video and send it back to you.
Very sorry if the above description is not correct.

Thank you.

@RobiNN1
Copy link
Contributor

RobiNN1 commented May 18, 2020

No need, issue is confirmed.

@Songohan22 Songohan22 changed the title BBCode URL Tag Script Injection "Shoutbox Admin" PHP Fusion 9.0.36 BBCode URL Tag Script Injection "Shoutbox" PHP Fusion 9.0.36 May 18, 2020
@Songohan22
Copy link
Author

@RobiNN1,
I Hope you fix it ASAP!
Thank you.

@r0ck3t1973
Copy link

RobiNN1 added a commit that referenced this issue May 19, 2020
@RobiNN1 RobiNN1 closed this as completed May 19, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants