Executive brief
b2evolution is a content management system used to host blogs and community websites. A security flaw in its Markdown plugin allows registered users to embed malicious scripts into posts or comments. If another user or administrator views this content, the script could execute in their browser, potentially leading to unauthorized actions or data theft.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in plugins/markdown_plugin/_markdown.plugin.php (specifically involving _parsedown.inc.php) in b2evolution versions prior to 6.8.5. The Markdown parser fails to properly validate or sanitize URLs used in links and images, allowing the use of the 'javascript:' URI scheme. An authenticated attacker can exploit this by creating content containing these malicious links; when a victim clicks the link or views the rendered page, arbitrary JavaScript executes in the context of their session. The fix implemented in version 6.8.5 restricts allowed URL schemes to http://, https://, or relative paths starting with /.
Affected products
- b2evolution b2evolution before 6.8.5
Timeline
- 2017-01-19: patched: Version 6.8.5 released with security fixes.
- 2017-01-23: disclosed: NVD publication date.