Executive brief
MeshCentral is a remote management and control platform used to administer servers and devices. A cross-site websocket hijacking vulnerability in its control.ashx endpoint allows an attacker to hijack an authenticated administrator's session by tricking them into visiting a malicious site, potentially enabling unauthorized administrative actions, secret leakage, and token generation. The attack requires specific conditions such as subdomain compromise or XSS, but when successful can lead to complete platform compromise.
Technical details
The vulnerability is a cross-site websocket hijacking (CSWSH) flaw in the control.ashx endpoint, which is MeshCentral's primary administrative interface. The endpoint lacks proper origin validation for websocket connections, allowing an attacker-controlled origin to establish a websocket connection to the victim's authenticated session. An attacker must convince a logged-in user to visit an attacker-controlled page (via a malicious link) or exploit a nearby subdomain takeover or XSS vulnerability on the same parent domain. The SameSite=Lax cookie setting provides partial mitigation by blocking cross-domain exploitation, but does not prevent same-domain or subdomain attacks. A successful exploit can read the server configuration file, leak the sessionKey variable, generate login tokens, and forge authentication cookies. The patch is available in version 1.1.21 and later.
Affected products
- MeshCentral MeshCentral before 1.1.21
Timeline
- 2024-02-19: disclosed
- 2024-02-19: patched: Fixed in version 1.1.21