Executive brief
KeystoneJS is an open-source Node.js CMS and content management framework. A cross-site scripting (XSS) vulnerability in versions prior to 4.0.0 allows attackers with administrative access to inject malicious JavaScript into blog posts that executes in the browsers of other users viewing those posts, potentially enabling session hijacking, credential theft, or defacement.
Technical details
KeystoneJS fails to properly encode rendered HTML in admin-created blog posts, resulting in a stored cross-site scripting (XSS) vulnerability (CWE-79). An attacker with administrative privileges can inject arbitrary JavaScript into blog post content. When other users view the compromised blog post, the malicious script executes in their browser with the privileges of their session. The attack requires admin-level account access and user interaction (victims must view the infected post). The vulnerability was fixed in version 4.0.0-beta7 and later.
Affected products
- KeystoneJS keystone < 4.0.0
Timeline
- 2017-11-16: disclosed
- 2017: patched: Fixed in version 4.0.0-beta7