Joomseller Events Booking Pro / JSE Event Cross Site Scripting

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1044666 漏洞类型
发布时间 2013-08-06 更新时间 2013-08-06
漏洞平台 N/A CVSS评分 N/A
 Joomseller "Events Booking Pro" and "JSE Event" reflected XSS

[+] Software Link:

[+] Affected Versions:

Component com_events_booking_v5
Component com_jse_event < 1.0.1

[+] Vulnerability Description:

The vulnerable files are the following:

.- For JSE Event:

.-For Events Booking pro:

The "info" parameter is not correctly sanitized before being used,
allowing an attacker to perform XSS attacks.

As a proof of concept, an attacker could perform the following request:

where the contents of the info parameter is the following payload
encoded using base64 encoding

{"events":"(15:00:00) <script>alert(1);</script>", "event_id":"64",
"itemid":"1", "evr_id":"1191"}

[+] Solution:

Upgrade to JSE Event version 1.0.1.

[+] Report Timeline:

[30/07/2013] - Vulnerability reported to the vendor
[30/07/2013] - Developer confirm vulnerability and update released
[05/08/2013] - Public disclosure

[+] Credits:

Vulnerability discovered by Gaston Traberg.