Junglewise Threat Intelligence

CVE-2017-5515: GeniXCMS cross-site scripting in user prompt function

CVE-2017-5515 · Severity: medium · CVSS 5.4 · Published 2017-01-17

Technologies: Metalgenix Genixcms. Vendors: Metalgenix.

Executive brief

GeniXCMS, a content management system used for building websites, contains a security flaw in its user prompt functionality. An authenticated user can inject malicious scripts that execute in the browsers of other users, potentially leading to unauthorized actions or the theft of sensitive session information. This could compromise the integrity of the website and the security of its visitors.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in GeniXCMS versions up to and including 0.0.8. The flaw is located within the user prompt function, where the application fails to properly neutralize user-supplied input in tag names. A remote authenticated attacker can exploit this by injecting malicious JavaScript or HTML. When other users interact with the affected prompt, the script executes in their browser context. This can lead to session hijacking, unauthorized administrative actions, or defacement of the web interface. A patch was referenced in historical issue tracking, though the original repository link is now inactive.

Affected products

  • GeniXCMS GeniXCMS through 0.0.8

Timeline

  • 2017-01-17: disclosed
  • 2017-01-17: advisory

References

Related threats