/plushcap/analysis/sonar/who-are-you-the-importance-of-verifying-message-origins

Who are you? The Importance of Verifying Message Origins

What's this blog post about?

SonarCloud detected a Cross-Site Scripting (XSS) vulnerability via event listener (CVE-2023-46252) and an authenticated Arbitrary File Write (CVE-2023-46253) in Squidex version 7.8.2 and below, which allowed attackers to gain remote code execution on a vulnerable Squidex instance by tricking a user into clicking on a malicious link. Both vulnerabilities were fixed with Squidex version 7.9.0. The missing origin check in the event listener function was exploited by attackers to craft a malicious link, triggering an XSS attack and combining it with the arbitrary file write vulnerability for remote code execution.

Company
Sonar

Date published
Jan. 28, 2024

Author(s)
Stefan Schiller

Word count
1203

Hacker News points
None found.

Language
English


By Matt Makai. 2021-2024.