File Upload Bypass Leads to Stored XSS in cockpit-hq/cockpit
Reported on
Aug 13th 2023
Description
In the file upload feature, the system did not allow uploading files with extensions like html, ... But when uploading files with extension xhtml
, it leads to XSS vulnerabilities.
Proof of Concept
https://drive.google.com/file/d/1_MTa4st4POafaUAwn17n7ygp_TrF9BXp/view?usp=sharing
Impact
Through the hole. attacker can execute malicious code
Occurrences
References
SECURITY.md
exists
4 months ago