PT-2024-31783 · Wire Ui · Wire Ui

Sharathdn1

·

Published

2024-09-17

·

Updated

2024-10-07

·

CVE-2024-45803

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Wire UI versions prior to 1.19.3 Wire UI versions prior to 2.1.3
Description: A potential Cross-Site Scripting (XSS) vulnerability has been identified in the "/wireui/button" endpoint, specifically through the label query parameter. Malicious actors could exploit this vulnerability by injecting JavaScript into the label parameter, leading to the execution of arbitrary code in the victim's browser. The "/wireui/button" endpoint dynamically renders button labels based on user-provided input via the label query parameter. Due to insufficient sanitization or escaping of this input, an attacker can inject malicious JavaScript. If exploited, this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the affected website, leading to session hijacking, user impersonation, phishing, or content manipulation.
Recommendations: For versions prior to 1.19.3, upgrade to version 1.19.3 or later. For versions prior to 2.1.3, upgrade to version 2.1.3 or later. As a temporary workaround, consider restricting access to the "/wireui/button" endpoint until a patch is available. Avoid using the label parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-45803
GHSA-RW5H-G8XQ-6877

Affected Products

Wire Ui