Executive brief
Exponent CMS, a content management system used for building and managing websites, contains a security flaw in its file upload system. An attacker can upload malicious HTML files that, when accessed by other users or administrators, execute unauthorized scripts in their browser. This could lead to the theft of login sessions, unauthorized website changes, or the compromise of user accounts.
Technical details
Exponent CMS versions prior to 2.3.7 are vulnerable to stored cross-site scripting (XSS) due to insufficient file type validation in the elFinder file management component. A remote attacker can upload a file with an .html extension containing malicious JavaScript. When a user or administrator subsequently accesses or previews this file through the elFinder interface, the script executes within the context of the victim's browser session. This can be used to hijack sessions or perform actions on behalf of the authenticated user. The issue was addressed in version 2.3.7 by strengthening server security parameters for upload folders and restricting how elFinder opens files.
Affected products
- Exponent CMS Exponent CMS before 2.3.7
Timeline
- 2015-12-25: disclosed: Vulnerability reported to vendor by Sachin Wagh
- 2015-12-26: patched: Fix committed to GitHub repository
- 2017-01-18: advisory: NVD publication date