PT-2022-15830 · Recipes · Recipes
Vabene1111
·
Published
2022-06-21
·
Updated
2022-06-28
·
CVE-2022-23072
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Recipes versions 1.0.5 through 1.2.5
Description
The issue concerns Stored Cross-Site Scripting (XSS) in the "Add to Cart" functionality. When a victim accesses the food list page, adds a new Food with a malicious javascript payload in the
Name parameter, and clicks on the Add to Shopping Cart icon, an XSS payload will trigger. This could allow a low-privileged attacker to obtain the victim's API key, potentially leading to admin's account takeover.Recommendations
For versions 1.0.5 through 1.2.5, as a temporary workaround, consider disabling the "Add to Cart" functionality or restricting the use of the
Name parameter in the affected API endpoint until a patch is available. Avoid using the Name parameter in the "Add to Cart" functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Recipes