Junglewise Threat Intelligence

CVE-2018-25349: userSpice XSS via X-Forwarded-For header in audit logs

CVE-2018-25349 · Severity: medium · CVSS 6.1 · Published 2026-05-23

Executive brief

userSpice, an open-source PHP user management framework, is vulnerable to a security flaw where malicious scripts can be hidden in web traffic headers. An attacker can send a specially crafted request that stores a malicious script in the system's audit logs. When an administrator later views these logs to monitor the system, the script executes in their browser, potentially allowing the attacker to steal session information or perform unauthorized actions with administrative privileges.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in userSpice version 4.3.24 and earlier due to improper neutralization of the 'X-Forwarded-For' HTTP header before it is recorded in the audit logs. An unauthenticated remote attacker can send a crafted GET request to the 'backup.php' endpoint containing a malicious JavaScript payload in the 'X-Forwarded-For' header. The payload is stored in the database and subsequently executed in the context of an administrator's browser session when they visit the audit log page. This can result in session hijacking, unauthorized configuration changes, or other actions performed on behalf of the authenticated administrator. A proof-of-concept exploit has been publicly disclosed.

Affected products

  • userSpice userSpice 4.3.24 and earlier

Timeline

  • 2018-06-10: disclosed: Initial discovery and PoC development by Dolev Farhi
  • 2018-06-11: other: Exploit published on Exploit-DB
  • 2026-05-23: advisory: CVE-2018-25349 published via VulnCheck/NVD

References

Related threats