Store XSS in Widgets and pages in instantsoft/icms2

Valid

Reported on

Aug 25th 2023


Description I noticed that you filtered the comment very carefully.

But there are still some parts you missed

Proof of Concept

1 .Login with admin

2 .Go to "https://demo.instantcms.io/admin/widgets"

3 . Insert payload in Position name and Title

 test" onmouseover = "alert(document.cookie)

4 .Click save , and detect store xss

Video Poc

https://drive.google.com/file/d/14rOcvhHlY7vmcCkks1fbl4KMt3XLd4lp/view?usp=sharing

Impact

This security vulnerability has the potential to steal multiple users' cookies, gain unauthorized access to that user's account through stolen cookies, or redirect the user to other malicious websites...

We are processing your report and will contact the instantsoft/icms2 team within 24 hours. a month ago
haido modified the report
a month ago
haido
a month ago

Researcher


Hi, I have prepared a backup VideoPoc: https://drive.google.com/file/d/1k2dcISjPhhH4B5LeRIxGHiwCbmGVFf53/view?usp=drive_link

We have contacted a member of the instantsoft/icms2 team and are waiting to hear back a month ago
haido
24 days ago

Researcher


hi, any update for this?

haido
24 days ago

Researcher


Hi @instantsoft/icms2, Hope you are interested in this report, thanks a lot.

Fuze modified the Severity from Critical (9.9) to Low (3.5) 24 days ago
The researcher has received a minor penalty to their credibility for miscalculating the severity: -1
Fuze validated this vulnerability 24 days ago

This kind of XSS is not inherently XSS. Only formally. The site administrator, who has access to the admin area, will not do it himself. And even if his account is compromised, it makes no sense for an attacker to use XSS. I'll verify your report with only one meaning, to keep you searching. But you should familiarize yourself better with the CMS.

haido has been awarded the disclosure bounty
The fix bounty is now up for grabs
The researcher's credibility has increased: +7
haido
24 days ago

Researcher


Yes. Can you specify a CVE for it. I need it for work. Thank you very much.

haido
22 days ago

Researcher


Hi @Fuza, can you specify the CVE for this report. I really need it for work. Thank you very much.

haido
21 days ago

Researcher


Hi @Fuze, can you specify the CVE for this report. I really need it for work. Thank you very much.

haido
19 days ago

Researcher


@Fuze, Can you help me with this problem? Thank you very much .

haido
16 days ago

Researcher


@Fuze? any update on this?

Fuze marked this as fixed in 2.16.1.-git with commit d0aeea 11 days ago
Fuze has been awarded the fix bounty
This vulnerability has been assigned a CVE
Fuze published this vulnerability 11 days ago
haido
11 days ago

Researcher


yes,thank you 😍.

to join this conversation