PT-2023-20449 · Teler-Waf · Teler-Waf
Aidil Arief
+1
·
Publicado
2023-03-01
·
Atualizado
2023-03-10
·
CVE-2023-26047
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
teler-waf versions prior to 0.2.0
Description
teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. The issue allows an attacker to execute arbitrary JavaScript code on the victim's browser and compromise the security of the web application when a specific case-sensitive hex entities payload with special characters such as CR/LF and horizontal tab is used. An attacker can exploit this to bypass common web attack threat rules in teler-waf and launch cross-site scripting (XSS) attacks, potentially stealing sensitive information or taking control of the victim's browser.
Recommendations
For versions prior to 0.2.0, update to version 0.2.0 or later to patch the vulnerability. As a temporary workaround, consider restricting the handling of special characters in payloads until the update can be applied.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Teler-Waf