Junglewise Threat Intelligence

CVE-2024-29271: VvvebJs reflected XSS in save.php action parameter

CVE-2024-29271 · Severity: low · CVSS 3.1 · Published 2024-03-22

Technologies: VvvebJs.

Executive brief

VvvebJs is a JavaScript page builder and design tool. A reflected cross-site scripting (XSS) vulnerability in the save.php file allows attackers to execute arbitrary code in a victim's browser by crafting a malicious link. An attacker could steal session cookies, credentials, or sensitive page content, or perform actions on behalf of the victim.

Technical details

A reflected XSS vulnerability (CWE-79) exists in VvvebJs versions before 1.7.5 in the save.php file's action parameter. The vulnerability stems from unsanitized user input from the GET parameter "action" being directly reflected into HTML error messages without escaping or filtering. An attacker can craft a link containing JavaScript payload (e.g., `?action=<script>alert('test')</script>`) and trick a user into clicking it; when loaded, the script executes in the victim's browser within the application's security context. The attack requires user interaction (clicking a link) and succeeds against any user who clicks the malicious URL. The vulnerability was patched in version 1.7.5.

Affected products

  • VvvebJs VvvebJs before 1.7.5

Timeline

  • 2024-03-11: disclosed: Issue reported on GitHub
  • 2024-03-22: advisory: GHSA and CVE published
  • 2024-03-22: patched: Fixed in version 1.7.5

References