Skip to main content
Medium November 16, 2009

ZenCart 1.3.8a Multiple XSS in Admin Interface

ZenCart 1.3.8a has a persistent XSS in 'Admin Home' in 'Last Name' parameter. Another Cross Site Scripting vulnerability exists in 'nogrants' parameter in sqlpatch.php.

CVSS Score

5.4 / 10.0

Severity

Medium

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Advisory

ApplicationZenCart
Version1.3.8a
ImpactPersistent and reflected XSS in the admin interface
Websec AdvisoryWS10-05

Background

ZenCart is a free, open-source e-commerce shopping cart.

Description

Persistent XSS in Admin Home. The Last Name field on the user registration form is stored without sanitization and rendered into the Admin Home page, so any script in that field runs in the administrator's browser on every visit to the dashboard.

Reflected XSS in sqlpatch.php. The nogrants query parameter on /admin/sqlpatch.php is reflected into the response without encoding.

Exploit / Proof of Concept

Persistent XSS via registration:

URL:  /zencart/index.php?main_page=login
Last Name: "onmouseover=alert(0)>XSS<!

Reflected XSS in the admin patch tool:

/zencart/admin/sqlpatch.php?nogrants="style="display:block;width:100%25;height:100%25;border:2px%20solid%20red;"%20onmouseover="alert(1);

Workaround

Avoid browsing untrusted sites while logged into the ZenCart administrator interface until an upstream patch is installed.

Remediation

Upgrade ZenCart to a release that sanitizes the admin-home Last Name and sqlpatch.php nogrants parameters.

Share this advisory:

Related Security Advisories

Stay informed about other recent vulnerabilities and security advisories

Critical December 18, 2014

Command Execution and Backdoor in Zhone GPON-2520

This post will describe a backdoor account found in the Zhone GPON-2520 and will provide a PoC which can be used to disable the firewall filtration rules in order to allow access to services such as ssh, telnet and ftp.

Severity:
CVSS: 9.8
View advisory
High May 22, 2014

Huawei HG8245 / HG8247 WPA Generator

Huawei HG8245 & HG8247 ONT (firmware version V1R006C00S100) rely on a weak algorithm to calculate the WPA keys, keys can be predicted easily using the WiFi's MAC Address (BSSID).

Severity:
CVSS: 7.4
View advisory
High December 19, 2013

Arbitrary Command Execution in Alcatel-Lucent I-240W-Q

The Alcatel-Lucent I-240W-Q ONT's Diagnostics page does not filter shell metacharacters in the IP address field, allowing any authenticated administrator to execute arbitrary commands as root and fully compromise the device.

Severity:
CVSS: 8.0
View advisory