Description
userSpice 4.3.24 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the X-Forwarded-For HTTP header. Attackers can send crafted requests to the backup.php endpoint with XSS payloads in the X-Forwarded-For header that execute when administrators visit the audit log page.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Dolev Farhi
References
www.exploit-db.com/exploits/44871 (ExploitDB-44871)
www.vulncheck.com/...te-scripting-via-x-forwarded-for-header (VulnCheck Advisory: userSpice 4.3.24 Cross-Site Scripting via X-Forwarded-For Header)