Executive brief
The hexo-admin plugin is a Node.js package that provides a web-based admin interface for managing Hexo blog content, including post editing. A stored cross-site scripting (XSS) vulnerability in the post editor allows attackers to inject malicious JavaScript that executes when other administrators or users view the affected post, potentially leading to account compromise or unauthorized actions.
Technical details
The vulnerability is a stored XSS flaw (CWE-79) in the post editor functionality of hexo-admin versions 2.3.0 and earlier. Attackers can inject JavaScript payloads via post content that are stored in the database and executed in the browser of any user viewing that post, without proper sanitization or encoding. The attack requires network access to the admin interface but no authentication bypass; an attacker with legitimate or stolen admin credentials can inject the payload. The vulnerability allows theft of session cookies, CSRF token manipulation, and unauthorized post modifications. Patches are available in versions after 2.3.0.
Affected products
- hexo-admin hexo-admin 2.3.0 and earlier
Timeline
- 2019-04-14: disclosed: Vulnerability reported via GitHub issue #185
- 2019-10-23: other: CVE-2019-17606 published
- 2022-05-24: advisory: GHSA-g784-q3p3-26rm advisory published