Junglewise Threat Intelligence

CVE-2015-8667: Exponent CMS cross-site scripting in Reset Your Password module

CVE-2015-8667 · Severity: medium · CVSS 6.1 · Published 2017-01-18

Technologies: Exponent Cms. Vendors: Exponentcms.

Executive brief

Exponent CMS, a content management system used for building and managing websites, contains a security flaw in its password reset feature. An attacker can use this vulnerability to inject malicious scripts into the website, which could lead to the theft of user session information or unauthorized actions being performed in a user's browser. This could compromise the accounts of website visitors or administrators who interact with the affected page.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Exponent CMS versions prior to 2.3.5. The flaw is located within the 'Reset Your Password' module, specifically due to insufficient sanitization of user-supplied input in the 'Username/Email' field. A remote, unauthenticated attacker can exploit this by tricking a user into clicking a specially crafted link, allowing the execution of arbitrary JavaScript or HTML in the context of the victim's browser session. This can result in session hijacking or unauthorized modification of page content. The issue was addressed in version 2.3.6 by implementing improved input sanitization logic.

Affected products

  • Exponent CMS Exponent CMS before 2.3.5

Timeline

  • 2015-12-24: disclosed: Vulnerability reported by Sachin Wagh
  • 2015-12-24: patched: Fix committed to GitHub repository
  • 2017-01-18: advisory: NVD published the CVE record

References

Related threats