PT-2023-20449 · Teler-Waf · Teler-Waf

Aidil Arief

+1

·

Published

2023-03-01

·

Updated

2023-03-10

·

CVE-2023-26047

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions teler-waf versions prior to 0.2.0
Description teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. The issue allows an attacker to execute arbitrary JavaScript code on the victim's browser and compromise the security of the web application when a specific case-sensitive hex entities payload with special characters such as CR/LF and horizontal tab is used. An attacker can exploit this to bypass common web attack threat rules in teler-waf and launch cross-site scripting (XSS) attacks, potentially stealing sensitive information or taking control of the victim's browser.
Recommendations For versions prior to 0.2.0, update to version 0.2.0 or later to patch the vulnerability. As a temporary workaround, consider restricting the handling of special characters in payloads until the update can be applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-26047
GHSA-P2PF-G8CQ-3GQ5
GO-2023-1600

Affected Products

Teler-Waf