Junglewise Threat Intelligence

@berslucas/liljs cross-site scripting via innerHTML

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

liljs is a lightweight JavaScript library for binding data to HTML elements. The library unsafely uses the innerHTML function to render user-supplied data without sanitization, allowing attackers to inject arbitrary JavaScript code that executes in victims' browsers. This can lead to session hijacking, credential theft, or malware distribution.

Technical details

This is a Stored or Reflected Cross-Site Scripting (XSS) vulnerability (CWE-79) in the liljs data-binding library. The vulnerability exists because the library uses JavaScript's innerHTML function to bind untrusted user data to DOM elements without sanitizing or escaping the input. An attacker can craft a malicious input containing JavaScript code (e.g., <img src=x onerror=alert('xss')>) that will be rendered and executed in the victim's browser when the library processes it. The attack requires user interaction (UI:R) to visit a page containing the vulnerable library. The vulnerability was fixed in version 1.0.2 by replacing innerHTML with textContent, which does not interpret HTML markup.

Affected products

  • @berslucas liljs prior to 1.0.2

Timeline

  • 2020-09-03: disclosed
  • 2020-09-03: patched: version 1.0.2 released with fix

References