Executive brief
Valine is a comment system embedded in websites to allow visitor feedback. The system fails to properly sanitize the commenter's name field, allowing attackers to inject malicious JavaScript code that executes in the browsers of all subsequent visitors who view the affected page. This can lead to theft of session credentials, account takeover, or malware distribution to site visitors.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in Valine versions prior to 1.4.15, caused by insufficient input validation on the nick parameter when submitting comments via the /classes/Comment endpoint. An unauthenticated attacker can inject arbitrary HTML and JavaScript into a comment's nick field by sending a specially crafted POST request; the malicious payload is stored on the server and executed in the browsers of all users who subsequently view the page containing that comment. The attack requires the attacker to be able to submit comments (possibly controlled by the comment platform's configuration), but does not require user interaction beyond the victim viewing the comment. A fix is available in version 1.4.15 and later.
Affected products
- xCss Valine before 1.4.15
Timeline
- 2020-11-11: disclosed: Vulnerability reported via GitHub issue #348
- 2022-04-06: patched: Advisory published; fix released in version 1.4.15
- 2022-04-06: advisory: GHSA-6xvq-2gj8-4276 published