[Bugcrowd] Stored XSS via Latex Input
Description
Note from QA:
The issue has been successfully reproduced on both QA and PROD environments. It affects both regular and inline macro versions.
The below description has been copied from the original bugcrowd submission.
Issue
Hello,
I found an stored XSS vulnerability via Latex Input. As an attacker, I can enter a phishing/malware website or take JWT auth. If successful, a XSS attack can severely impact websites and web applications, damage reputation and relationships with customers. XSS can deface websites, can result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device.
Payload :
$$\href{javascript:alert(location.href)}{Click me}$$
Steps to reproduce
-
Go to blogs/pages and choose Macro Pack
-
Choose Latex Input with Source Text Input and then fill with payload
-
Insert
-
When victim click link, XSS will popup
Impact
-
Account takeover or JWT auth takeover
-
If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user.
-
Create phishing/malware website.
QA pass completed, issue is fixed and no regressions found. Ready to merge.