TinyMCE Image Manager Plugin Cross Site Scripting and Arbitrary File Upload Vulnerabilities
BID:61368
Info
TinyMCE Image Manager Plugin Cross Site Scripting and Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 61368 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2013 12:00AM |
| Updated: | Jul 18 2013 12:00AM |
| Credit: | MustLive |
| Vulnerable: |
TinyMCE Image Manager 1.1 |
| Not Vulnerable: | |
Discussion
TinyMCE Image Manager Plugin Cross Site Scripting and Arbitrary File Upload Vulnerabilities
The Image Manager plugin for TinyMCE is prone to a cross-site-scripting vulnerability and an arbitrary file-upload vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, upload arbitrary files and steal cookie-based authentication credentials.
Image Manager 1.1 is vulnerable; other versions may also be affected.
The Image Manager plugin for TinyMCE is prone to a cross-site-scripting vulnerability and an arbitrary file-upload vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, upload arbitrary files and steal cookie-based authentication credentials.
Image Manager 1.1 is vulnerable; other versions may also be affected.
Exploit / POC
TinyMCE Image Manager Plugin Cross Site Scripting and Arbitrary File Upload Vulnerabilities
Attackers can exploit arbitrary file-upload issue through a browser. To exploit the cross-site scripting issue, an attacker must entice an unsuspecting user into following a malicious URI.
Attackers can exploit arbitrary file-upload issue through a browser. To exploit the cross-site scripting issue, an attacker must entice an unsuspecting user into following a malicious URI.
Solution / Fix
TinyMCE Image Manager Plugin Cross Site Scripting and Arbitrary File Upload Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
TinyMCE Image Manager Plugin Cross Site Scripting and Arbitrary File Upload Vulnerabilities
References:
References:
- AFU and XSS vulnerabilities in TinyMCE Image Manager (MustLive)
- Image Manager Download Page (Dustweb)