{"id":"GHSA-ggwq-xc72-33r3","summary":"LGSL has a reflected XSS at /lgsl_files/lgsl_list.php","details":"# Reflected XSS at /lgsl_files/lgsl_list.php\n\n\n**Description:**\n\nVulnerability: A reflected XSS vulnerability exists in the `Referer` HTTP header of [LGSL v6.2.1](https://github.com/tltneon/lgsl/releases/tag/v6.2.1). The vulnerability allows attackers to inject arbitrary JavaScript code, which is reflected in the HTML response without proper sanitization.\nWhen crafted malicious input is provided in the `Referer` header, it is echoed back into an HTML attribute in the application’s response.\n\n\nThe vulnerability is present at [Line 20-24](https://github.com/tltneon/lgsl/blob/master/lgsl_files/lgsl_list.php#L20-L24)\n```php\n  $uri = $_SERVER['REQUEST_URI'];\n\n  if ($lgsl_config['preloader']) {\n    $uri = $_SERVER['HTTP_REFERER'];\n  }\n```\n\n**Proof of Concept:**\n1. Capture a request to the path `/lgsl_files/lgsl_list.php`.\n2. Inject the following payload into the Referer header: `test'\u003e\u003cscript\u003ealert(1)\u003c/script\u003e\u003c`.\n3. Send the request.\n4. The XSS payload is triggered when reloading.\n![image](https://github.com/user-attachments/assets/467a6c60-db45-4520-9918-59dff819b384)\n![image](https://github.com/user-attachments/assets/c537c59e-38c2-47f0-97d8-54ee1b2018b8)\n\n\n\n**Impact:**\n\nExecution of Malicious Code\n\n","aliases":["CVE-2024-56517"],"modified":"2024-12-30T18:53:37.039895Z","published":"2024-12-30T16:49:28Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-12-30T16:49:28Z","nvd_published_at":"2024-12-30T17:15:09Z"},"references":[{"type":"WEB","url":"https://github.com/tltneon/lgsl/security/advisories/GHSA-ggwq-xc72-33r3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56517"},{"type":"WEB","url":"https://github.com/tltneon/lgsl/commit/7ecb839df9358d21f64cdbff5b2536af25a77de1"},{"type":"PACKAGE","url":"https://github.com/tltneon/lgsl"},{"type":"WEB","url":"https://github.com/tltneon/lgsl/blob/master/lgsl_files/lgsl_list.php#L20-L24"}],"affected":[{"package":{"name":"tltneon/lgsl","ecosystem":"Packagist","purl":"pkg:composer/tltneon/lgsl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.2.1"}]}],"versions":["v5.10.0","v5.10.1","v5.10.2","v5.10.3","v6.0.0","v6.0.1","v6.1.0","v6.1.1","v6.2.0","v6.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-ggwq-xc72-33r3/GHSA-ggwq-xc72-33r3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}