HTML Injection Leads To Open Redirect in omeka/omeka-s

Valid

Reported on

Jul 27th 2023


Description

HTML injection is possible in the Installation title parameter, which leads to Open Redirect when clicked.

Proof of Concept Open Redirect

  1. Login as Admin
  2. Navigate to settings
  3. Edit the Installation title and set it to:
<a href=https://evil.com>Click Me</a>
  1. Save Changes
  2. Click the Click Me text on the top left of the page

Screenshots

  1. Open Redirect Video POC

Impact

The combination of an open redirect vulnerability and HTML injection can lead to phishing attacks, malware distribution, and compromised user data.

We are processing your report and will contact the omeka/omeka-s team within 24 hours. 2 months ago
M0ck3d modified the report
2 months ago
M0ck3d modified the report
2 months ago
M0ck3d modified the report
2 months ago
M0ck3d modified the report
2 months ago
M0ck3d modified the report
2 months ago
M0ck3d modified the report
2 months ago
M0ck3d modified the report
2 months ago
M0ck3d modified the report
2 months ago
M0ck3d modified the report
2 months ago
M0ck3d modified the report
2 months ago
We have contacted a member of the omeka/omeka-s team and are waiting to hear back 2 months ago
omeka/omeka-s maintainer has acknowledged this report 2 months ago
M0ck3d modified the report
2 months ago
John Flatness validated this vulnerability 2 months ago
M0ck3d has been awarded the disclosure bounty
The fix bounty is now up for grabs
The researcher's credibility has increased: +7
M0ck3d
2 months ago

Researcher


@zerocrates @maintainer I noticed that the fix for this was committed last week. Would it be possible to assign a CVE and publish this vulnerability ? Thank you kindly!

John Flatness
2 months ago

Maintainer


We just have to get our ducks in a row for a release. It should be pretty soon.

M0ck3d
2 months ago

Researcher


@zerocrates No worries ! Thank you for the update !

John Flatness marked this as fixed in 4.0.3 with commit 8b7261 2 months ago
The fix bounty has been dropped
This vulnerability has been assigned a CVE
John Flatness published this vulnerability 2 months ago
SettingForm.php#L130-L142 has been validated
to join this conversation