Browsershot 3.57.2 - Server Side XSS to LFR via HTML
7.5
High
Discovered by

Offensive Team, Fluid Attacks
Summary
Full name
Browsershot 3.57.2 - Server Side XSS to LFR via HTML
Code name
State
Public
Release date
Oct 28, 2022
Affected product
Browsershot
Affected version(s)
Version 3.57.2
Vulnerability name
Server Side XSS
Vulnerability type
Remotely exploitable
Yes
CVSS v3.1 vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1 base score
7.5
Exploit available
Yes
CVE ID(s)
Description
Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the HTML content passed to the Browsershot::html
method does not contain URL's that use the file://
protocol.
Vulnerability
This vulnerability occurs because the application does not validate that the HTML content passed to the Browsershot::html
method does not contain URL's that use the file://
protocol.
Exploitation


Our security policy
We have reserved the CVE-2022-43983 to refer to these issues from now on. Disclosure policy
System Information
Version: Browsershot 3.57.2
Operating System: GNU/Linux
Mitigation
An updated version of Browsershot is available at the vendor page.
References
Timeline
Vulnerability discovered
Oct 25, 2022
Vendor Confirmed Vuln.
Oct 25, 2022
Vulnerability patched
Oct 25, 2022
Vendor contacted
Oct 25, 2022
Vendor replied
Oct 25, 2022
Public disclosure
Oct 28, 2022