webssh2 icon indicating copy to clipboard operation
webssh2 copied to clipboard

Cross Site Script (XSS) attack on at least the `header` url param

Open elongstreet88 opened this issue 1 year ago • 0 comments

You can execute a xss using at least the header url param (didnt check others, but assume the same for anything page rendering).

Ex: http://localhost:2222/ssh/host/mydevice.local?header=<img src=x onerror=alert('XSS')>

Output: image

The params would need to be sanitized properly to avoid rendering on the page.

elongstreet88 avatar Oct 26 '23 03:10 elongstreet88