Executive brief
hexo-theme-anzhiyu is a popular theme for the Hexo static blog generator. The theme's Algolia search integration contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts through search inputs. An attacker can exploit this flaw to steal visitor credentials, deface blog content, or redirect users to malicious sites.
Technical details
The vulnerability is a reflected cross-site scripting (XSS) flaw (CWE-79, CWE-80) in hexo-theme-anzhiyu v1.6.12 that occurs in the Algolia search function. The theme fails to properly sanitize or escape user-supplied input from the search box before rendering it in the DOM. An attacker can craft a malicious search query containing JavaScript code that executes in the victim's browser when they perform a search. The attack requires user interaction (clicking search) and works via network access; no authentication is required. A patch or fix version is expected but specific version details were not provided in the advisory.
Affected products
- anzhiyu-c hexo-theme-anzhiyu 1.6.12
Timeline
- 2024-02-09: disclosed
- 2024-03-03: advisory