Executive brief
Saltcorn Server is an open-source low-code application framework that manages tables, views, and event logs. A stored cross-site scripting (XSS) vulnerability in the event logs page allows lower-privileged users (e.g., staff) to inject malicious JavaScript that executes when administrators view the affected log entries, potentially compromising admin accounts or sensitive operations.
Technical details
The vulnerability is a stored XSS flaw (CWE-79) in the event log display route (eventlog.js line 445) that fails to sanitize user-supplied payload data before inserting it into HTML. An attacker with table read/write permissions can insert malicious JavaScript (e.g., <svg/onload=alert()>) via table data; when an administrator views the corresponding event log entry, the unescaped payload is rendered as executable code. The attack requires prior application access and event logging to be enabled, but no special privileges are needed to inject the payload. The vulnerability was patched in version 1.0.0-beta.16 by escaping event body content in the log display.
Affected products
- Saltcorn Server <=1.0.0-beta.13
Timeline
- 2024-10-07: disclosed
- 2024-10-07: patched: version 1.0.0-beta.16