Executive brief
iziModal is a jQuery-based modal dialog plugin used by web developers to display popup windows. The plugin fails to properly sanitize the title parameter when creating modals, allowing attackers to inject malicious JavaScript code that executes in the context of users viewing the affected pages. This could lead to session hijacking, credential theft, or malware distribution.
Technical details
The vulnerability is a Stored/Reflected Cross-Site Scripting (XSS, CWE-79) in iziModal versions prior to 1.6.1. The vulnerable component is the modal title handler, which does not sanitize or escape user-supplied input before rendering it in the DOM. An attacker who can control the title parameter passed to iziModal can inject arbitrary HTML and JavaScript. The attack requires network access and some form of user interaction (the victim must trigger the modal). An attacker can execute arbitrary JavaScript in the victim's browser session. The fix is available in version 1.6.1.
Affected products
- marcelodolza iziModal < 1.6.1
Timeline
- 2023-02-21: disclosed
- 2023-02-21: patched: Fixed in version 1.6.1