{"id":"GHSA-7c4c-749j-pfp2","summary":"Admidio Vulnerable to HTML Injection In The Messages Section","details":"### Summary\nAn unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server.\n\n### PoC\n1. Go to\nhttps://www.admidio.org/demo_en/adm_program/modules/messages/messages.php\n2. Click on Send Private Message\n3. In the `Message` field, enter the following payload\n`Testing\u003cbr\u003e\u003ch1\u003eHTML\u003c/h1\u003e\u003cbr\u003e\u003ch2\u003eInjection\u003c/h2\u003e`\n\n\u003e \n![image](https://github.com/user-attachments/assets/0e5d9e4e-69c5-4908-9ab9-0c45c2548ff8)\n\n4. Send the message\n5. Open the message again\n\n\u003e \n![image](https://github.com/user-attachments/assets/d36f1b64-7d96-486d-ab65-cce2b7d21428)\n\n\n### Impact\n1. Data Theft: Stealing sensitive information like cookies, session tokens, and user credentials.\n2. Session Hijacking: Gaining unauthorized access to user accounts.\n3. Phishing: Tricking users into revealing sensitive information.\n4. Website Defacement: Altering the appearance or content of the website.\n5. Malware Distribution: Spreading malware to users' devices.\n6. Denial of Service (DoS): Overloading the server with malicious requests.","aliases":["CVE-2024-47836"],"modified":"2024-10-16T22:26:07.747718Z","published":"2024-10-16T19:50:40Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-10-16T19:50:40Z","nvd_published_at":"2024-10-16T20:15:06Z","cwe_ids":["CWE-502","CWE-79"],"severity":"LOW"},"references":[{"type":"WEB","url":"https://github.com/Admidio/admidio/security/advisories/GHSA-7c4c-749j-pfp2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47836"},{"type":"WEB","url":"https://github.com/Admidio/admidio/commit/176f60de6a38dde2b8e848b97647194c12cf5a6c"},{"type":"PACKAGE","url":"https://github.com/Admidio/admidio"}],"affected":[{"package":{"name":"admidio/admidio","ecosystem":"Packagist","purl":"pkg:composer/admidio/admidio"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.3.12"}]}],"versions":["4.1.0","4.1.3","v4.2-Beta.1","v4.2-Beta.2","v4.2-Beta.3","v4.2.0","v4.2.1","v4.2.10","v4.2.11","v4.2.12","v4.2.13","v4.2.14","v4.2.2","v4.2.3","v4.2.4","v4.2.5","v4.2.6","v4.2.7","v4.2.8","v4.2.9","v4.3-Beta.1","v4.3-Beta.3","v4.3-Beta.4","v4.3-Beta.5","v4.3.0","v4.3.1","v4.3.10","v4.3.11","v4.3.2","v4.3.3","v4.3.4","v4.3.5","v4.3.6","v4.3.7","v4.3.8","v4.3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-7c4c-749j-pfp2/GHSA-7c4c-749j-pfp2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"}]}