Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a poll that is automatically loaded in the DOM once the thread/topic is opened. Because session cookies lack the HttpOnly flag, it is possible to steal authentication cookies and take over accounts.
References
Link | Resource |
---|---|
https://codologic.com/forum/index.php?u=/topic/12638/codoforum-4-8-8-released-and-the-future#post-23845 | Release Notes Vendor Advisory |
https://www.linkedin.com/posts/polina-voronina-896819b5_discovered-by-polina-voronina-jan-15-activity-6634436086540054528-dDgg/ | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-02-15T17:52:46
Updated: 2020-02-15T17:53:40
Reserved: 2020-01-14T00:00:00
Link: CVE-2020-7050
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-02-15T18:19:50.890
Modified: 2022-06-28T14:11:45.273
Link: CVE-2020-7050
JSON object: View
Redhat Information
No data.