Junglewise Threat Intelligence

CVE-2019-11004: Materialize-css XSS in Toast feature

CVE-2019-11004 · Severity: low · CVSS 3 · Published 2019-04-09

Technologies: materialize-css (npm), @materializecss/materialize (npm). Vendors: npm.

Executive brief

Materialize-css is a popular CSS framework providing UI components like toasts, tooltips, and autocomplete. The framework fails to sanitize untrusted HTML input before rendering these components, allowing an attacker to inject malicious scripts that execute in users' browsers and steal sensitive data like cookies or session tokens.

Technical details

Materialize-css versions through 1.0.0 contain a Cross-Site Scripting (XSS) vulnerability in the Toast, Tooltip, and Autocomplete components due to improper neutralization of input during web page generation (CWE-79). The vulnerable code uses jQuery's .html() method or equivalent to render user-supplied data directly into the DOM without sanitization. An attacker can inject malicious HTML and JavaScript through dynamic content (e.g., user-supplied messages displayed in toasts, tooltip text, or autocomplete suggestions). The attack requires user interaction in the web page but no prior authentication. A fix is available in version 1.1.0-alpha of the @materializecss/materialize package.

Affected products

  • Materialize materialize-css through 1.0.0
  • Materialize materialize before 1.1.0-alpha

Timeline

  • 2019-02-08: disclosed: Vulnerability reported via GitHub issue #6286
  • 2019-04-09: advisory: GHSA-rg3q-jxmp-pvjj published

References

Related threats