PhpSocial v2.0.0304: XSSDate: 2015-12-21 10:59:38
|Affected Product:||PhpSocial v2.0.0304_20222226|
|Fixed in:||not fixed|
|Fixed Version Link:||n/a|
|Vulnerability Type:||XSS / Open Redirect|
|Reported to vendor:||11/21/2015|
|Disclosed to public:||12/21/2015|
|Release mode:||Full Disclosure|
|Credits||Tim Coen of curesec GmbH|
Medium 5.0 AV:N/AC:L/Au:N/C:N/I:P/A:N
PhpSocial is a social networking software written in PHP. In version v2.0.0304, the profile fields Name, Birthday, Street Address, City, State, Country, and Phone Number are open to persistent XSS.
3. Proof of Concept
Visit Profile: http://localhost/PhpSocial_v2.0.0304_20222226/cms_phpsocial/Profile.php?user=[USERNAME] Click edit and use the following for any of the vulnerable fields: <img src=no onerror=alert(1)>
4. Open Redirect
Low 2.1 AV:N/AC:H/Au:S/C:N/I:P/A:N
PhpSocial is also vulnerable to a reflected open redirect, which may for example be used in phishing attacks. The attack only works if the victim is logged in to PhpSocial.
Proof of Concept
This issue was not fixed by the vendor.
6. Report Timeline
|11/21/2015||Contacted Vendor (no reply)|
|12/10/2015||Tried to remind vendor (no email is given, firstname.lastname@example.org does not exist, and contact form could not be used because the website is down)|
|12/21/2015||Disclosed to public|