PT-2022-17163 · Proton · Proton
Oscar Uribe
·
Published
2022-05-20
·
Updated
2022-05-31
·
CVE-2022-25224
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Proton version 0.2.0
Description
The issue allows an attacker to create a malicious link inside a markdown file. When the victim clicks the link, the application opens the site in the current frame, allowing an attacker to host JavaScript code in the malicious link in order to trigger an XSS attack. The 'nodeIntegration' configuration is set to on, which allows the webpage to use NodeJs features. An attacker can leverage this to run OS commands.
Recommendations
For Proton version 0.2.0, consider disabling the 'nodeIntegration' configuration to prevent the webpage from using NodeJs features until a patch is available. Restrict access to markdown files that may contain malicious links to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Proton