CVE-2010-1916: High severity Xinha WYSIWYG editor vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-1916 to the following vulnerability:
Name: CVE-2010-1916 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1916 Assigned: 20100511 Reference: MISC: http://www.php-security.org/2010/05/10/mops-2010-019-serendipity-wysiwyg-editor-plugin-configuration-injection-vulnerability/index.html Reference: MISC: http://www.php-security.org/2010/05/10/mops-2010-020-xinha-wysiwyg-plugin-configuration-injection-vulnerability/index.html
The dynamic configuration feature in Xinha WYSIWYG editor 0.96 Beta 2 and earlier, as used in Serendipity 1.5.2 and earlier, allows remote attackers to bypass intended access restrictions and modify the configuration of arbitrary plugins via (1) crafted backendconfigsecretkeylocation and backendconfighash parameters that are used in a SHA1 hash of a shared secret that can be known or externally influenced, which are not properly handled by the "Deprecated config passing" feature; or (2) crafted backenddata and backenddata[keylocation] variables, which are not properly handled by the xinhareadpasseddata function. NOTE: this can be leveraged to upload and possibly execute arbitrary files via config.inc.php in the ImageManager plugin.
The upstream bug report [1] has links to patches to correct this issue.
[1] http://trac.xinha.org/ticket/1518
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1916?
CVE-2010-1916 has a medium severity rating due to its potential impact on application configuration and access control.
How do I fix CVE-2010-1916?
To mitigate CVE-2010-1916, ensure that the plugin configuration settings are secured and review access permissions for files associated with the Xinha WYSIWYG editor.
Which versions of software are affected by CVE-2010-1916?
CVE-2010-1916 affects multiple versions of the Xinha WYSIWYG editor ranging from 0.9-beta to 0.96-beta2, as well as various versions of the Serendipity (S9Y) Freetag Event.
What type of vulnerability is CVE-2010-1916?
CVE-2010-1916 is classified as a configuration injection vulnerability that can allow unauthorized access to sensitive areas of an application.
How can I find out more about CVE-2010-1916?
Further details on CVE-2010-1916 can be found in security advisories and reports related to the affected software versions.