CVE-2019-17625

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
16/10/2019
Last modified:
16/10/2019

Description

There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for Node.js and Electron, such as an exec of OS commands within the onerror attribute of an IMG element.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rambox:rambox:0.6.9:*:*:*:community:*:*:*


References to Advisories, Solutions, and Tools