Actions
Bug #17009
openPotential XSS via rule descriptions in the Suricata Rules page
Start date:
Due date:
% Done:
100%
Estimated time:
Plus Target Version:
Affected Version:
Affected Plus Version:
Affected Architecture:
Description
The Suricata Rules page (suricata_rules.php) does not encode rule descriptions or other data before display.
The rule descriptions can be supplied by custom rules or untrusted external sources which could contain a problematic payload, potentially leading to XSS.
For example:
alert icmp any any -> any any (msg:"xss<img src=x onerror=alert(String.fromCharCode(88,83,83))>"; itype:8; sid:990064640; rev:1;)
If the administrator views the suricata_rules.php page with a Category that renders the rules table such as "Active Rules" containing one of these entries, it can trigger an XSS.
Reported by: @lujiefsi
Actions
Also available in: Atom