Executive brief
Mavo is a web development library that allows users to create data-driven websites using only HTML and CSS. A vulnerability in how the library loads plugins allows an attacker to trick the software into loading malicious scripts from an external server. This could lead to unauthorized code execution (Cross-Site Scripting) on websites using the affected version of the library, potentially compromising user data or site integrity.
Technical details
A DOM Clobbering vulnerability exists in Mavo v0.3.2 within its plugin-loading mechanism. The library uses 'document.currentScript' to determine the base URL for loading dependencies. An attacker can inject a non-script HTML element (such as an <img> tag with name='currentScript') to shadow the legitimate 'document.currentScript' property. By controlling the 'src' attribute of the clobbered element, the attacker can redirect the library to load plugin dependencies from an attacker-controlled domain, resulting in Cross-Site Scripting (XSS). A fix involves verifying that 'document.currentScript' actually refers to a SCRIPT element before accessing its attributes.
Affected products
- mavoweb mavo 0.3.2
Timeline
- 2025-03-03: advisory: GHSA-3mf5-r4hg-hfx9 published
- 2025-03-03: disclosed: CVE-2024-53388 published