Intel

AIKIDO-2024-10298

meshcentral is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Sep 27, 2024

50

Medium Risk

This Affects:

jsmeshcentral
0.0.1 - 1.1.30
Fixed in 1.1.31
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to Cross-site Scripting (XSS). Multiple XSS vulnerabilities exist, such as the possibility of constructing a filename that, when edited, executes a script. Additionally, an attacker can construct a URL like https://localhost/meshagents?key="><script>alert(1)</script><a+ to exploit the vulnerability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

meshcentral is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 1.1.30.

How to fix this

Upgrade the meshcentral library to the patch version.