Skip to main content
Medium October 13, 2009

Commonspot CMS 5.1.0.x Cross Site Scripting vulnerabilities

Multiple reflected cross-site scripting vulnerabilities in PaperThin's CommonSpot CMS 5.0 and 5.1, reachable through loader.cfm, let an attacker hijack an administrator session or stage CSRF and phishing attacks against the platform.

CVSS Score

6.1 / 10.0

Severity

Medium

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Advisory

VendorPaperThin
SoftwareCommonSpot CMS
Vulnerable Versions5.0.x through 5.1 (tested on 5.1.0.128, 5.0.3.132, 5.0.2.56)
ImpactCredential theft, CSRF, phishing via reflected XSS
Solution StatusNot fixed

Background

CommonSpot by PaperThin is a commercial content management system. Business users author and publish content through loader.cfm and its supporting modules.

Description

Parameters passed to loader.cfm are reflected into the response without sanitization. An attacker who lures a logged-in admin to click a crafted URL can execute arbitrary JavaScript in that admin's browser, steal session credentials, issue CSRF requests against the CMS, or stage phishing.

Exploit / Proof of Concept

loader.cfm?csModule=security/email-login-info&errmsg=<img%20src=%27x%27%20onerror=%22alert%280%29;%22>&bNewWindow=0

Remediation

Upgrade Commonspot CMS to a patched release; no fix was issued by PaperThin for 5.0.x–5.1.x at disclosure.

Share this advisory:

Related Security Advisories

Stay informed about other recent vulnerabilities and security advisories

Critical December 18, 2014

Command Execution and Backdoor in Zhone GPON-2520

This post will describe a backdoor account found in the Zhone GPON-2520 and will provide a PoC which can be used to disable the firewall filtration rules in order to allow access to services such as ssh, telnet and ftp.

Severity:
CVSS: 9.8
View advisory
High May 22, 2014

Huawei HG8245 / HG8247 WPA Generator

Huawei HG8245 & HG8247 ONT (firmware version V1R006C00S100) rely on a weak algorithm to calculate the WPA keys, keys can be predicted easily using the WiFi's MAC Address (BSSID).

Severity:
CVSS: 7.4
View advisory
High December 19, 2013

Arbitrary Command Execution in Alcatel-Lucent I-240W-Q

The Alcatel-Lucent I-240W-Q ONT's Diagnostics page does not filter shell metacharacters in the IP address field, allowing any authenticated administrator to execute arbitrary commands as root and fully compromise the device.

Severity:
CVSS: 8.0
View advisory