XSS and Full Path Disclosure in MijoSearch Joomla Extension
Advisory ID: | HTB23186 |
Product: | MijoSearch |
Vendor: | Mijosoft |
Vulnerable Versions: | 2.0.1 and probably prior |
Tested Version: | 2.0.1 |
Advisory Publication: | November 25, 2013 [without technical details] |
Vendor Notification: | November 25, 2013 |
Public Disclosure: | December 16, 2013 |
Vulnerability Type: | Cross-Site Scripting [CWE-79] Information Exposure Through Externally-generated Error Message [CWE-211] |
CVE References: | CVE-2013-6878 CVE-2013-6879 |
Risk Level: | Medium |
CVSSv2 Base Scores: | 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N) |
Discovered and Provided: | High-Tech Bridge Security Research Lab |
Advisory Details: | |
High-Tech Bridge Security Research Lab discovered 2 vulnerabilities in MijoSearch Joomla Extension, which can be exploited to gain access to potentially sensitive data and perform Cross-Site Scripting (XSS) attacks against users of vulnerable application. | |
Solution: | |
Currently we are not aware about any vendor-supplied patches or solutions. It's recommended to deactivate the vulnerable extension. Vendor notification and disclosure timeline: 2013-11-25 Vendor notified via online ticket system Vendor denies any vulnerabilities Vendor authorizes us to test his website Vulnerabilities reproduced (screenshots available) Vendor still denies the vulnerabilities 2013-11-26 Vendor provided with exact version of vulnerable system Vendor still denies the vulnerabilities Vendor refuses to collaborate Vendor refuses to confirm other vulnerable version(s) Vendor bans one of our IPs on online ticket system 2013-12-14 Vendor suspends our user account on online ticket system Vendor contacted again by all available emails 2013-12-16 No single reply from the vendor. | |
References: | |
[1] High-Tech Bridge Advisory HTB23186 - https://www.immuniweb.com/advisory/HTB23186 - Multiple Vulnerabilities in MijoSearch. [2] MijoSearch - http://mijosoft.com/joomla-extensions/mijosearch-joomla-search-engine - MijoSearch is flexible and powerful Joomla Search component with an easy-to-use interface. [3] Common Vulnerabilities and Exposures (CVE) - http://cve.mitre.org/ - international in scope and free for public use, CVE® is a dictionary of publicly known information security vulnerabilities and exposures. [4] Common Weakness Enumeration (CWE) - http://cwe.mitre.org - targeted to developers and security practitioners, CWE is a formal list of software weakness types. [5] ImmuniWeb® - Leveraging the power of machine-learning and genius of human brain to deliver the most advanced web application security and penetration testing. [6] ImmuniWeb® SSLScan - Test your servers for security and compliance with PCI DSS, HIPAA and NIST. | |
Please feel free to send us any additional information related to this Advisory, such as vulnerable versions, additional exploitation details and conditions, patches and other relevant details.