Junglewise Threat Intelligence

Vendure admin-ui-plugin authenticated cross-site scripting in descriptions

Severity: info · Published 2023-07-06

Vendors: npm.

Executive brief

Vendure's admin UI plugin allows authorized administrators to create descriptions for collections, shipping methods, promotions, and other catalog items. A flaw allows authenticated users to inject arbitrary HTML and JavaScript into these description fields by modifying request data directly, bypassing the WYSIWYG editor's sanitization. When other administrators view these pages, the malicious script executes in their browser, allowing attackers to perform actions with their privileges—a form of privilege escalation.

Technical details

This is a stored cross-site scripting (XSS) vulnerability (CWE-79) in the admin UI's rich text editor for description fields. The vulnerable component fails to sanitize HTML when description data is saved via direct API requests, even though the WYSIWYG editor enforces some restrictions. An authenticated user with permission to create or edit descriptions can bypass the editor's controls and inject malicious HTML/JavaScript, which is then stored and executed in the browsers of any user who views the affected page. The attack requires prior authentication but no additional user interaction beyond viewing a crafted description. The fix was released in version 2.0.3, which adds proper HTML sanitization to prevent XSS payload execution.

Affected products

  • Vendure admin-ui-plugin < 2.0.3

Timeline

  • 2023-07-06: disclosed
  • 2023-07-04: patched: Version 2.0.3 released with fix

References