Executive brief
Huashengdun WebSSH is a web-based terminal emulator that allows users to access SSH servers through a browser. A security flaw in the login page allows attackers to inject malicious scripts into the application by tricking a user into clicking a specially crafted link. If successful, an attacker could perform unauthorized actions in the user's browser session, such as stealing session information or redirecting the user to malicious websites.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Huashengdun WebSSH versions prior to 1.6.3. The application fails to properly sanitize or encode user-supplied input provided via the 'hostname' and 'port' GET parameters on the login page before reflecting them in the HTML response. A remote attacker can exploit this by enticing a user to visit a malicious URL containing a JavaScript payload. Successful exploitation allows for the execution of arbitrary script code in the context of the victim's browser session. The issue was addressed in version 1.6.3.
Affected products
- Huashengdun WebSSH < 1.6.3
Timeline
- 2025-04-09: disclosed: Vulnerability reported via GitHub issue and PoC published.
- 2025-07-20: advisory: GitHub and NVD advisories published.
- 2025-07-20: patched: Version 1.6.3 released to address the issue.