Junglewise Threat Intelligence

CVE-2019-13970: AntSword XSS leading to code execution in database configuration

CVE-2019-13970 · Severity: low · CVSS 3 · Published 2022-05-24

Executive brief

AntSword is a web shell management and penetration testing tool used by security professionals and attackers. A self-XSS vulnerability in the database configuration interface allows an attacker to inject malicious JavaScript code that, when processed by the application, can execute arbitrary commands on the system hosting AntSword.

Technical details

The vulnerability is a self-XSS flaw in the database configuration functionality (affecting modules/database/asp/index.js, modules/database/custom/index.js, modules/database/index.js, and modules/database/php/index.js) that fails to properly sanitize user input in the database address field. An attacker can inject JavaScript payloads through the database configuration page, and when the input is processed, the injected code executes with full application privileges, enabling remote code execution. The attack requires user interaction (the attacker or victim must access the database configuration page), but no authentication bypass is needed if the AntSword instance is already accessible. The vulnerability was patched in version 2.1.0.

Affected products

  • AntSword AntSword before 2.1.0

Timeline

  • 2019-04-18: disclosed
  • 2019-07-19: patched: Version 2.1.0 released with fix
  • 2022-05-24: advisory: GHSA published

References