Miggo Logo

CVE-2017-8298:
Canvs Canvas Cross-site Scripting (XSS) via title and content fields

5.4

CVSS Score

Basic Information

EPSS Score
-
Published
5/17/2022
Updated
1/10/2024
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
austintoddj/canvascomposer= 3.3.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

While no specific code is available, the pattern suggests controller methods handling CRUD operations for posts/tags/users are vulnerable. XSS occurs when: 1) User input from title/content fields is stored without proper sanitization 2) Stored data is rendered in views without output encoding. The confidence is medium due to lack of direct code evidence, but aligns with standard MVC vulnerability patterns in PHP applications and the advisory's described attack vectors.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

*nvs.io **nv*s *.*.* **s XSS in t** titl* *n* *ont*nt *i*l*s o* * "Posts > *** N*w" **tion, *n* *urin* *r**tion o* n*w t**s *n* us*rs.

Reasoning

W*il* no sp**i*i* *o** is *v*il**l*, t** p*tt*rn su***sts *ontroll*r m*t*o*s **n*lin* *RU* op*r*tions *or posts/t**s/us*rs *r* vuln*r**l*. XSS o**urs w**n: *) Us*r input *rom titl*/*ont*nt *i*l*s is stor** wit*out prop*r s*nitiz*tion *) Stor** **t* i