Junglewise Threat Intelligence

CVE-2023-30094: TotalJS stored cross-site scripting in settings

CVE-2023-30094 · Severity: low · CVSS 3.1 · Published 2023-05-04

Technologies: TotalJS Total4. Vendors: npm.

Executive brief

TotalJS is a Node.js framework and platform for building web applications. A stored cross-site scripting (XSS) vulnerability in the settings module allows authenticated users to inject malicious scripts into the platform name field, which are then executed when other users view the settings. This could enable account hijacking, credential theft, or unauthorized actions performed on behalf of affected users.

Technical details

The vulnerability is a stored XSS (CWE-79) in TotalJS's settings module, specifically in the platform name field. Malicious JavaScript payloads injected into this field are not properly sanitized or escaped, allowing them to persist in storage and execute in the browsers of all users who subsequently access the settings page. The attack requires authentication to inject the payload and user interaction (viewing the settings page) to trigger execution. Affected versions prior to 0.0.81 of the total4 package are vulnerable; the fix is available in version 0.0.81 and later.

Affected products

  • TotalJS total4 before 0.0.81

Timeline

  • 2023-05-04: disclosed: Advisory published
  • 2023-05-04: patched: Fix available in version 0.0.81

References

Related threats