The page a shared image link opens (the share mini page) links the article the image was shared from when the option Share article links is on. It took the address of the article from the shared link and printed it into the page without checking or escaping it, and with the link type Image Page with Redirect it followed the address at once. A prepared link could therefore run a script in the page, in the session of the visitor who opened it, or send the visitor to another web site. Nothing on the server is changed or read by the server.
- Needed: the option Share article links on; it is off by default. No account; the victim is any visitor who opens a prepared link.
- Affected: 3.11.6, which brought the option, to 6.5.0, 4.3.3 included.
- Fixed in: 6.6.0. The page follows only an address of your own site, links the event otherwise, and escapes the address. Shared links keep working.
-
Severity: CVSS 4.0 2.3 (
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N), CWE-79 and CWE-601. - CVE: not assigned yet.
All prices include VAT. The gross price will vary depending on the selected shipping country.