PT-2023-5024 · Alteryx · Alteryx Server

Dylangrl

·

Published

2023-08-08

·

Updated

2023-08-21

·

CVE-2023-26961

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Alteryx Server version 2022.1.1.42590
Description The issue exists due to the lack of protection for the web page structure in Alteryx Server, allowing remote attackers to perform cross-site scripting (XSS) attacks via the type field using a PUT request to the "/gallery/api/media" endpoint. This vulnerability also enables attackers to upload arbitrary files, such as JavaScript content for stored XSS, by changing the file extension.
Recommendations For Alteryx Server version 2022.1.1.42590, consider disabling the ability to upload files via the "/gallery/api/media" endpoint until a patch is available. Restrict access to the type field in the JSON document within the PUT request to minimize the risk of exploitation. As a temporary workaround, implement file type verification for uploaded files to prevent attackers from uploading arbitrary files.

Exploit

Fix

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05563
CVE-2023-26961

Affected Products

Alteryx Server