PT-2018-17760 · Cozy · Cozy
Published
2018-02-07
·
Updated
2018-02-27
·
CVE-2018-6824
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cozy version 2
Description
The issue allows remote attackers to obtain administrative access via JavaScript code in the
url parameter to the "/api/proxy" API endpoint. This can be achieved through an XMLHttpRequest call with a request containing email:"attacker@example.com", potentially followed by a password reset.Recommendations
For Cozy version 2, as a temporary workaround, consider restricting access to the "/api/proxy" API endpoint until a patch is available. Avoid using the
url parameter in this endpoint to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cozy