Exponent CMS 2.6.0 patch2 - Stored XSS (User-Agent)
5,4
Medium
Discovered by
Offensive Team, Fluid Attacks
Summary
Full name
Exponent CMS 2.6.0 patch2 - Stored XSS (User-Agent)
Code name
State
Public
Release date
Affected product
Exponent CMS
Vendor
Exponent CMS
Affected version(s)
v2.6.0 patch2
Fixed version(s)
2.7.0
Vulnerability name
Stored cross-site scripting (XSS)
Vulnerability type
Remotely exploitable
Yes
CVSS v3.1 vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v3.1 base score
5.4
Exploit available
No
CVE ID(s)
Description
Exponent CMS 2.6.0 patch2 allows an authenticated user to inject persistent javascript code on the User-Agent when logging in. When an administratoruser visits the 'User Sessions' tab, the javascript will be triggered allowingan attacker to compromise the administrator session.
PoC
Use a Web proxy or a tool to modify the browser User-agent with the following PoC.
Try to login with a non-admin user.
If an admin user visits 'User Management' > 'User Sessions' the XSS will be triggered.
A non-admin user may compromise an admin session by exploiting this vulnerability.
Our security policy
We have reserved the ID CVE-2022-23049 to refer to this issue from now on.
System Information
Version: Exponent CMS 2.6.0 patch2.
Operating System: Linux.
Web Server: Apache
PHP Version: 7.4
Database and version: Mysql
References
Vendor page: https://www.exponentcms.org/index.php
GitHub repository: https://github.com/exponentcms/exponent-cms
Ticket: https://exponentcms.lighthouseapp.com/projects/61783/tickets/1461
Issue: https://github.com/exponentcms/exponent-cms/issues/1546
Patch: https://github.com/exponentcms/exponent-cms/commit/4eec1a2d6def4a5369bda5fd63472dd706ea957a
Exploit
There is no exploit for the vulnerability but can be manually exploited.
Mitigation
An updated version of Exponent CMS is available on the vendor page.
Credits
The vulnerability was discovered by Oscar Uribe from Fluid Attacks' Offensive Team.
Timeline
Vulnerability discovered
Vendor contacted
Vulnerability patched
Public disclosure
Does your application use this vulnerable software?
During our free trial, our tools assess your application, identify vulnerabilities, and provide recommendations for their remediation.














