CVE-2016-20098: Moderator Toolbox before 4.0.14 Stored XSS via Removal Reasons Configuration
Moderator Toolbox (reddit-moderator-toolbox) before 4.0.14 contains a stored cross-site scripting vulnerability in the removalreasons module, which inserts subreddit toolbox wiki fields into popup HTML without encoding. Attackers who can edit the toolbox wiki page can plant JavaScript in fields like pmsubject, header, or reason titles to act with moderators' Reddit sessions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
reddit-moderator-toolboxto a version that resolves this vulnerability.Fixed in 4.0.14
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Moderators using Moderator Toolbox versions before 4.0.14 are exposed when they open removal-reasons popups that render attacker-controlled fields from the subreddit toolbox wiki page. The impact is tied to the moderator's active Reddit session.
What level of access does an attacker need?
An attacker must be able to edit the subreddit’s toolbox wiki page. They can place JavaScript in removal-reasons configuration fields such as pmsubject, header, or reason titles.
How can I determine whether our configuration may be malicious?
Review the removalreasons configuration on the subreddit toolbox wiki page, particularly pmsubject, header, and reason-title fields, for injected JavaScript or unexpected HTML/script content. Any such content may execute when rendered in a removal-reasons popup on affected versions.
What is the available remediation?
Upgrade Moderator Toolbox to version 4.0.14 or later. If upgrading cannot happen immediately, restrict editing access to the toolbox wiki page and remove untrusted content from the affected removal-reasons fields.