Executive brief
pekeupload is a JavaScript file upload library used by web applications to allow users to upload files. A vulnerability exists where filenames containing JavaScript code are not properly sanitized before display, allowing an attacker to execute arbitrary JavaScript in a user's browser by convincing them to upload a file with a malicious name. This could lead to session hijacking, credential theft, or defacement.
Technical details
The vulnerability is a Stored Cross-site Scripting (XSS) flaw in the pekeupload library (CWE-79). When a user uploads a file with a filename containing JavaScript code, the filename is rendered in the page without proper HTML encoding or escaping. An attacker can craft a filename such as "<img src=x onerror=alert(1)>" and induce a user to upload it; the JavaScript payload will execute in the victim's browser with their privileges. This affects all versions of pekeupload up to and including version 2.1.1. The attack requires user interaction (uploading the malicious file) and network access, but no authentication is required. A patch has not been confirmed in the advisory as of the publication date.
Affected products
- moxiecode pekeupload all versions up to 2.1.1
Timeline
- 2021-11-22: disclosed: Published on NVD
- 2021-12-02: advisory: GitHub Security Advisory published