Junglewise Threat Intelligence

CVE-2021-46871: Phoenix HTML cross-site scripting in HEEx class attributes

CVE-2021-46871 · Severity: low · CVSS 3.1 · Published 2023-01-10

Vendors: npm.

Executive brief

Phoenix HTML is a library for building HTML components in the Phoenix web framework. A cross-site scripting (XSS) vulnerability in the HEEx template language allows attackers to inject malicious scripts through class attributes when user input is not properly escaped. An attacker could exploit this to steal user credentials, perform actions on behalf of users, or redirect users to malicious sites.

Technical details

The vulnerability is a cross-site scripting (XSS) flaw in Phoenix HTML's HEEx templating engine, specifically in how class attributes are handled in the tag.ex component. The root cause is improper neutralization of user-controllable input before it is rendered in HTML class attributes (CWE-79). When developers use dynamic values in class attributes (e.g., class={@value}), the values were not properly escaped, allowing an attacker to inject arbitrary HTML or JavaScript. The attack requires no authentication and can be triggered via network-reachable templates rendering untrusted user input. A successful exploit allows arbitrary JavaScript execution in the victim's browser. The vulnerability was fixed in version 3.0.4; all versions prior to this release are affected.

Affected products

  • Phoenix Framework phoenix_html before 3.0.4

Timeline

  • 2023-01-10: disclosed
  • 2023-01-10: patched: Fixed in version 3.0.4

References