Executive brief
uBidAuction, a software platform used to create and manage online auction websites, contains a security flaw in its filtering tools. An attacker can send a specially crafted link to a user; if clicked, it allows the attacker to run malicious scripts in the user's web browser. This could lead to unauthorized access to user sessions, theft of sensitive information, or redirection to fraudulent websites.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in uBidAuction v2.0.1 due to improper sanitization of input parameters within the filter functionality. Specifically, the 'date_created', 'date_from', 'date_to', and 'created_at' parameters are vulnerable across several modules such as /tickets/manage, /orders/myOrders, and /auctions/manage. A remote, unauthenticated attacker can exploit this by tricking a user into clicking a crafted GET request. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or phishing. While the vendor was notified in early 2022, the current status of a formal patch is unconfirmed in the advisory text.
Affected products
- ApPHP uBidAuction 2.0.1
Timeline
- 2022-01-21: disclosed: Public disclosure by Vulnerability Laboratory
- 2022-09-02: other: Vendor notification
- 2026-05-10: advisory: NVD/VulnCheck advisory published