Cryptocat CVE-2013-4106 HTML Injection Vulnerability
BID:61099
CVE-2013-4106 |Info
Cryptocat CVE-2013-4106 HTML Injection Vulnerability
| Bugtraq ID: | 61099 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4106 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 07 2012 12:00AM |
| Updated: | Nov 07 2012 12:00AM |
| Credit: | Mario Heiderich, Krzysztof Kotowicz and Maxim Rupp |
| Vulnerable: |
Cryptocat Project Cryptocat 2.0.21 Cryptocat Project Cryptocat 2.0.20 Cryptocat Project Cryptocat 2.0.12 Cryptocat Project Cryptocat 2.0.11 Cryptocat Project Cryptocat 2.0.10 Cryptocat Project Cryptocat 2.0.1 Cryptocat Project Cryptocat 2.0 Cryptocat Project Cryptocat 2.0 |
| Not Vulnerable: |
Cryptocat Project Cryptocat 2.0.22 |
Discussion
Cryptocat CVE-2013-4106 HTML Injection Vulnerability
Cryptocat is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Cryptocat 2.0.22 are vulnerable.
Cryptocat is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Cryptocat 2.0.22 are vulnerable.
Exploit / POC
Solution / Fix
Cryptocat CVE-2013-4106 HTML Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cryptocat CVE-2013-4106 HTML Injection Vulnerability
References:
References:
- Cryptocat Changelog (Cryptocat)
- Cryptocat Homepage (Cryptocat)
- Cure53 Public Pentest Report: Cryptocat 2 (Dr.-Ing. Mario Heiderich, Krzysztof Kotowicz & Maxim Rupp )