Executive brief
iobroker.web is a Node.js-based web server for accessing ioBroker database files through a web interface. The vulnerability allows attackers to inject malicious JavaScript code through URL parameters that are reflected in the server response without proper escaping. An attacker can craft a malicious link that, when clicked by a user, executes arbitrary JavaScript in the victim's browser, potentially stealing session cookies or sensitive data.
Technical details
This is a reflected cross-site scripting (XSS) vulnerability in iobroker.web versions prior to 2.4.10, classified as CWE-79. The vulnerability exists because the application fails to properly escape URL parameters (GET request parameters) before reflecting them in the HTTP response. An unauthenticated attacker can deliver a malicious URL to a user; when the user's browser processes the response, the injected JavaScript executes with the privileges of the web application. The attack requires user interaction (clicking a malicious link) and has a network attack vector. The vulnerability is fixed in version 2.4.10 or later.
Affected products
- ioBroker iobroker.web < 2.4.10
Timeline
- 2019-11-07: disclosed
- 2019-12-02: advisory
- 2019-12-02: patched: Fixed in version 2.4.10