Cross-site Scripting (XSS) - Reflected in zikula/core

Valid

Reported on

Nov 29th 2021


Description

In zikula/core cross site scripting vulnerability in extension list name field.

Proof of Concept

  1. login to the demo account

  2. go to extensions https://demo.ziku.la/extensions/module/modify/3

  3. Add payload in displayname field

payload "><iMg SrC="x" oNeRRor="alert(1);">

Impact

This vulnerability is capable of stolen the user cookie

We are processing your report and will contact the zikula/core team within 24 hours. 2 months ago
We have contacted a member of the zikula/core team and are waiting to hear back 2 months ago
zikula/core maintainer validated this vulnerability 2 months ago
Asura-N has been awarded the disclosure bounty
The fix bounty is now up for grabs
zikula/core maintainer confirmed that a fix has been merged on e453ad 2 months ago
The fix bounty has been dropped