Executive brief
Typesetter CMS, an open-source content management system, contains a security flaw in its administrative interface. An attacker can trick a logged-in administrator into clicking a malicious link, allowing the attacker to run unauthorized scripts in the administrator's browser. This could lead to the theft of sensitive session information or unauthorized changes to the website.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Typesetter CMS versions up to 5.1. The flaw is located in 'include/admin/Tools/Status.php' where the 'path' parameter is reflected into the HTML output without proper encoding during move message handling. An authenticated attacker can exploit this by supplying crafted input containing HTML or JavaScript. Successful exploitation requires a victim with administrative privileges to interact with a malicious link, resulting in arbitrary script execution within the victim's browser session. As of the advisory date, the project appears to be unmaintained and no official patch has been confirmed.
Affected products
- Typesetter Typesetter CMS up to and including 5.1
Timeline
- 2025-03-09: disclosed: Issue reported on GitHub by Snow1nd
- 2026-01-14: advisory: NVD/VulnCheck advisory published