Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-23367: fulusso DOM-based XSS

Fulusso v1.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in /BindAccount/SuccessTips.js. This vulnerability allows attackers to inject malicious code into a victim user’s device via open redirection.

CVE
#xss#vulnerability#web#js#git#java

Vulnerability Report

target: fulusso version: 1.1

root cause

on front page React object, location.search query is parsed and used without any escape. When a victim succeeds login to the page from attacker’s link, malicious JS code can be injected and executed.

PoC

https://account.suuyuu.cn/login.html?ReturnUrl=javascript:alert(document.location)

this website is a demo site using fulusso which the authors provide.

login info id: 13111111111 pw: test1234

image

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907