Junglewise Threat Intelligence

CVE-2017-5516: GeniXCMS multiple XSS in user forms

CVE-2017-5516 · Severity: medium · CVSS 6.1 · Published 2017-01-17

Technologies: Metalgenix Genixcms. Vendors: Metalgenix.

Executive brief

GeniXCMS, a content management system used for building and managing websites, contains multiple security flaws in its user-facing forms. An attacker can use these flaws to inject malicious scripts into the web pages viewed by other users. This could lead to unauthorized actions being performed in a user's session, such as the theft of login cookies or the redirection of users to malicious websites.

Technical details

GeniXCMS versions up to and including 0.0.8 are vulnerable to multiple reflected Cross-Site Scripting (XSS) attacks. The vulnerability exists because the application fails to properly neutralize user-supplied input within various user forms before including it in generated HTML pages. A remote, unauthenticated attacker can exploit this by tricking a user into clicking a specially crafted link containing malicious parameters. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized data modification. A patch was reportedly addressed in the project's issue tracker.

Affected products

  • GeniXCMS GeniXCMS through 0.0.8

Timeline

  • 2017-01-17: advisory: Initial NVD publication
  • 2017-01-17: patched: Patch referenced in GitHub issue 65

References

Related threats