Junglewise Threat Intelligence

CVE-2019-17606: hexo-admin plugin stored XSS in post editor

CVE-2019-17606 · Severity: low · CVSS 3.1 · Published 2022-05-24

Vendors: npm.

Executive brief

The hexo-admin plugin is a Node.js package that provides a web-based admin interface for managing Hexo blog content, including post editing. A stored cross-site scripting (XSS) vulnerability in the post editor allows attackers to inject malicious JavaScript that executes when other administrators or users view the affected post, potentially leading to account compromise or unauthorized actions.

Technical details

The vulnerability is a stored XSS flaw (CWE-79) in the post editor functionality of hexo-admin versions 2.3.0 and earlier. Attackers can inject JavaScript payloads via post content that are stored in the database and executed in the browser of any user viewing that post, without proper sanitization or encoding. The attack requires network access to the admin interface but no authentication bypass; an attacker with legitimate or stolen admin credentials can inject the payload. The vulnerability allows theft of session cookies, CSRF token manipulation, and unauthorized post modifications. Patches are available in versions after 2.3.0.

Affected products

  • hexo-admin hexo-admin 2.3.0 and earlier

Timeline

  • 2019-04-14: disclosed: Vulnerability reported via GitHub issue #185
  • 2019-10-23: other: CVE-2019-17606 published
  • 2022-05-24: advisory: GHSA-g784-q3p3-26rm advisory published

References

Related threats