Junglewise Threat Intelligence

CVE-2016-1000235: fuelux cross-site scripting in Pillbox feature

CVE-2016-1000235 · Severity: info · CVSS 6.1 · Published 2020-09-01

Vendors: npm.

Executive brief

fuelux is a popular front-end library used to build interactive web interfaces. A cross-site scripting (XSS) vulnerability in the Pillbox component allows attackers to inject and execute arbitrary JavaScript by providing malicious input, potentially compromising user sessions, stealing sensitive data, or defacing pages.

Technical details

The vulnerability is a stored or reflected cross-site scripting (CWE-79) flaw in the fuelux Pillbox feature. An attacker can supply a script tag or other malicious payload as a value when creating a new pillbox element, and the application fails to properly sanitize or escape the input before rendering it in the DOM. This allows arbitrary JavaScript execution in the context of the affected web page. No authentication is required; the attack vector depends on how the Pillbox component is exposed in the application. The vulnerability was fixed in version 3.15.7.

Affected products

  • fuelux fuelux before 3.15.7

Timeline

  • 2020-09-01: disclosed
  • 2020-09-01: patched: fix available in version 3.15.7

References