Junglewise Threat Intelligence

CVE-2023-27474: Directus HTML injection in password reset email

CVE-2023-27474 · Severity: low · CVSS 3.1 · Published 2023-03-07

Technologies: directus (npm). Vendors: npm, Directus.

Executive brief

Directus is a headless CMS and backend platform that handles user authentication and password resets. The product fails to properly encode query parameters when generating password reset emails, allowing attackers to inject arbitrary HTML into reset emails sent to users. An attacker who can trigger a password reset with a custom reset URL can inject malicious content into the email, potentially for phishing, credential theft, or account takeover.

Technical details

The vulnerability is a cross-site scripting (CWE-79) flaw in Directus's password reset functionality. The root cause is improper URL encoding in the `/api/src/utils/url.ts` file, where query parameters are manually concatenated without RFC-compliant character handling. Specifically, URL-encoded query parameters are decoded and re-concatenated, causing special characters to be interpreted literally instead of remaining encoded. An attacker can exploit this by supplying a custom reset URL containing encoded characters (e.g., `sample%2Bvalue%21`) which are decoded in the resulting password reset email link, allowing HTML injection. This requires that the custom reset URL be on an allow-list configured by the Directus instance administrator. The vulnerability was patched in version 9.23.0 by correctly handling URL encoding. Affected versions are all releases up to and including 9.22.4.

Affected products

  • Directus directus <=9.22.4

Timeline

  • 2023-03-07: disclosed
  • 2023-03-07: patched: Fixed in version 9.23.0

References

Related threats