Exploit Report

Computer Security And Bug Information

CVE-2023-26047

CVECVE-2023-26047
CVE Title
Published Date2023-03-03T23:15Z
Modified Date2023-03-10T15:03Z
CWE TypeCWE-79
CVSS 3.xCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Descriptionteler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. In teler-waf prior to version v0.2.0 is vulnerable to a bypass attack when a specific case-sensitive hex entities payload with special characters such as CR/LF and horizontal tab is used. This vulnerability allows an attacker to execute arbitrary JavaScript code on the victim's browser and compromise the security of the web application. An attacker can exploit this vulnerability to bypass common web attack threat rules in teler-waf and launch cross-site scripting (XSS) attacks. The attacker can execute arbitrary JavaScript code on the victim's browser and steal sensitive information, such as login credentials and session tokens, or take control of the victim's browser and perform malicious actions. This issue has been patched in version 0.2.0.
References
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites.
Reference URLhttps://github.com/dwisiswant0/cwa-filter-rules/commit/d818d1645832d1a02cd210c7680e692d2bf4313b
Reference DescriptionMISC https://github.com/dwisiswant0/cwa-filter-rules/commit/d818d1645832d1a02cd210c7680e692d2bf4313b
Reference URLhttps://github.com/kitabisa/teler-waf/security/advisories/GHSA-p2pf-g8cq-3gq5
Reference DescriptionMISC https://github.com/kitabisa/teler-waf/security/advisories/GHSA-p2pf-g8cq-3gq5
Reference URLhttps://github.com/kitabisa/teler-waf/releases/tag/v0.2.0
Reference DescriptionMISC https://github.com/kitabisa/teler-waf/releases/tag/v0.2.0
TagsPatch
Sources NIST MITRE

This site's data is aggregated programmatically and provided "as is" without any representations or warranties, express or implied. Exploit.report is not affiliated with the The MITRE Corporation, U.S. Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), or US government in any way. CVE and the CVE logo are registered trademarks of The MITRE Corporation

© 2022 Exploit.Report | Data | Contact | Privacy Policy | Articles