Junglewise Threat Intelligence

CVE-2024-26318: Serenity cross-site scripting in login page return URL

CVE-2024-26318 · Severity: low · CVSS 3.1 · Published 2024-02-19

Technologies: Serenity.Net.Core (NuGet). Vendors: NuGet, npm.

Executive brief

Serenity is a web application development framework used to build business applications. The framework's login page accepted arbitrary return URLs from email links without proper validation, allowing attackers to craft phishing emails that execute malicious scripts when users clicked them. This could lead to credential theft, session hijacking, or malware distribution. The issue was remediated in version 6.8.0 by restricting return URLs to local paths only.

Technical details

This is a reflected cross-site scripting (CWE-79) vulnerability in the LoginPage.tsx component of Serenity. The root cause is insufficient validation of the return URL parameter passed to the login page, which was previously accepted regardless of its origin. An attacker can craft a malicious email containing a login link with a return URL pointing to an external domain or containing JavaScript (e.g., javascript: protocol or data: URI), which the page would redirect to or execute after authentication. The attack vector is primarily email-based social engineering combined with network access to the application. The fix validates that return URLs must begin with a forward slash (/), ensuring they point to internal application paths only. All versions before 6.8.0 are affected, across both the NuGet Serenity.Net.Core package and the npm @serenity-is/corelib package.

Affected products

  • Serenity Serenity.Net.Core before 6.8.0
  • Serenity @serenity-is/corelib before 6.8.0

Timeline

  • 2024-02-19: disclosed
  • 2023-08-14: patched: Fix released in version 6.8.0

References

Related threats