Executive brief
The Baremetrics date range picker is a widely-used JavaScript component for selecting date ranges on websites. A flaw in versions 1.0.14 and earlier allows attackers to inject malicious JavaScript code through the placeholder text field, which executes in visitors' browsers without restriction. This can lead to account hijacking, credential theft, malware distribution, or defacement of the affected website.
Technical details
The vulnerability is a reflected cross-site scripting (XSS) flaw in the Calendar.js file, classified as CWE-79. The root cause is improper sanitization of the placeholder parameter when rendering the input field. The vulnerable code directly concatenates the user-supplied placeholder into the DOM without HTML escaping. An attacker can supply a malicious placeholder value (e.g., 'Foobar"><img src="foobar" onerror="alert(3)" /><') that breaks out of the attribute context and injects arbitrary HTML or script tags. The attack requires the attacker to control or influence the placeholder setting at Calendar instantiation time, but does not require authentication or user interaction beyond page load. Successful exploitation results in arbitrary JavaScript execution in the victim's browser context. No patches are available; the project has been archived as unmaintained since April 2022.
Affected products
- Baremetrics date range picker 1.0.14 and prior
Timeline
- 2023-02-21: disclosed: GHSA-465f-mxxh-grc4 and CVE-2021-32859 published
- 2021-11-24: other: Vulnerability reported to maintainer via coordinated disclosure
- 2022-04-13: other: Project archived by owner and marked read-only; no patches issued