PT-2023-20449 · Teler-Waf · Teler-Waf

·

CVE-2023-26047

·

Published

2023-03-01

·

Updated

2023-03-10

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions teler-waf versions prior to 0.2.0
Description teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. The issue allows an attacker to execute arbitrary JavaScript code on the victim's browser and compromise the security of the web application when a specific case-sensitive hex entities payload with special characters such as CR/LF and horizontal tab is used. An attacker can exploit this to bypass common web attack threat rules in teler-waf and launch cross-site scripting (XSS) attacks, potentially stealing sensitive information or taking control of the victim's browser.
Recommendations For versions prior to 0.2.0, update to version 0.2.0 or later to patch the vulnerability. As a temporary workaround, consider restricting the handling of special characters in payloads until the update can be applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-26047
GHSA-P2PF-G8CQ-3GQ5
GO-2023-1600

Affected Products

Teler-Waf