PT-2023-20449 · Teler-Waf · Teler-Waf
Aidil Arief
+1
·
Published
2023-03-01
·
Updated
2023-03-10
·
CVE-2023-26047
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
teler-waf versions prior to 0.2.0
Description
teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. The issue allows an attacker to execute arbitrary JavaScript code on the victim's browser and compromise the security of the web application when a specific case-sensitive hex entities payload with special characters such as CR/LF and horizontal tab is used. An attacker can exploit this to bypass common web attack threat rules in teler-waf and launch cross-site scripting (XSS) attacks, potentially stealing sensitive information or taking control of the victim's browser.
Recommendations
For versions prior to 0.2.0, update to version 0.2.0 or later to patch the vulnerability. As a temporary workaround, consider restricting the handling of special characters in payloads until the update can be applied.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Teler-Waf