vendor:
MistServer
by:
John Page (aka Hyp3rlinX)
6,1
CVSS
MEDIUM
Unauthenticated Persistent XSS
N/A
CWE
Product Name: MistServer
Affected Version From: v2.12
Affected Version To: v2.12
Patch Exists: YES
Related CWE: CVE-2017-16884
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
Unauthenticated Persistent XSS
Unauthenticated remote attackers can inject persistent XSS payloads by making failed HTTP authentication requests. Attacker supplied payloads will get stored in the server logs as failed authentication requests alerts. Mistserver echoes back the unsanitized payloads in Mist Servers Web interface automatically due to automatic refresh of the UI every few seconds, thereby, executing arbitrary attacker supplied code.
Mitigation:
Update to the latest version of MistServer