usd-2020-0035 | Gambio GX 126.96.36.199
Advisory ID: usd-2020-0035
CVE Number: CVE-2020-10985
Affected Product: Gambio GX
Affected Version: 188.8.131.52
Vulnerability Type: Stored Cross-Site Scripting (XSS)
Security Risk: Medium
Vendor URL: https://www.gambio.de/
Vendor Status: Fixed in 184.108.40.206 (according to vendor)
The open source web application „Gambio GX“ is contains a XSS vulnerability. In the admin area multiple arguments that are passed while creating a new coupon code are vulnerable to XSS.
Stored cross-site scripting arises when an application receives data from an untrusted source and includes that data within its later HTTP responses in an unsafe way. The transferred inputs are not filtered or encoded before saving or during output.
Proof of Concept (PoC)
The following request can be send to the web application to create a new coupon. Multiple arguments in the request are vulnerable to XSS. For test purposes the XSS payloads were inserted into to the coupon_name and coupon_desc POST parameters.
- 2020-03-25 Vulnerability Discovered
- 2020-03-26 Initial Contact Request
- 2020-03-26 Advisory submitted to vendor
- 2020-05-04 Vendor publishes fix in Beta Version of Gambio GX 220.127.116.11 Beta1 https://tracker.gambio-server.net/issues/66736
- 2020-05 Vendor publishes 18.104.22.168 https://developers.gambio.de/changelog/#bugfix22.214.171.124
- 2020-06-18 Security advisory released
This security vulnerability was found by Gerbert Roitburd of usd AG.