Rapid7, a cybersecurity firm, recently revealed eight security flaws in four open source and freemium Document Management System (DMS) offerings from LogicalDOC, Mayan, ONLYOFFICE, and OpenKM. These vulnerabilities could allow an attacker to convince a human operator to save a malicious document on the platform, which would then give the attacker multiple paths to control the organization. The eight cross-site scripting flaws, discovered by Rapid7 researcher Matthew Kienow, are known as Stored XSS, which occurs when a malicious script is injected directly into a vulnerable web application. A threat actor could exploit these flaws by providing a decoy document, granting them the ability to steal the session cookie of a locally-logged in administrator and reuse it to create a new privileged account. Alternatively, the attacker could abuse the identity of the victim to inject arbitrary commands and gain access to the stored documents. The flaws were reported to the vendors on December 1, 2022, but remain unpatched. To protect against these vulnerabilities, users of the affected DMS are advised to be cautious when importing documents from unknown or untrusted sources, limit the creation of anonymous, untrusted users, and restrict certain features such as chats and tagging to known users.
This Cyber News was published on thehackernews.com. Publication date: Wed, 08 Feb 2023 18:08:02 +0000