Executive brief
Valine is a JavaScript comment system library used in websites to manage user comments. A vulnerability in versions up to 1.3.3 allows attackers to inject malicious HTML code into comments, which can be used to execute JavaScript code by embedding a PDF file, potentially leading to malware distribution, credential theft, or website defacement.
Technical details
Valine v1.3.3 and earlier contains a stored cross-site scripting (XSS) vulnerability via improper HTML input validation (CWE-79). An attacker can inject arbitrary HTML—specifically EMBED elements pointing to remotely hosted PDF files—into comments. Since EMBED tags bypass same-origin policy restrictions, the referenced PDF can contain JavaScript payloads that execute in the context of the victim's browser when the comment is viewed. This requires only network access and user interaction (viewing the page), with no authentication needed. The vulnerability was fixed in version 1.3.4 through HTML entity encoding of user input.
Affected products
- Valine Valine <=1.3.3
Timeline
- 2018-11-14: disclosed: Issue opened on GitHub
- 2018-11-21: advisory: GHSA-hhrp-qm88-xjr3 published
- 2018-11-21: patched: Fix released in v1.3.4 with HTML entity encoding