CVE-2024-54128: Directus has an HTML Injection in Comment
Summary The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which can be bypassed, making the application vulnerable to HTML Injection.
Details The Comment feature implements a character filter on the client-side, this can be bypassed by directly sending a request to the endpoint.
Example Request:
PATCH /activity/comment/3 HTTP/2 Host: directus.local
{ "comment": "<h1>TEST <p style=\"color:red\">HTML INJECTION</p> <a href=\"//evil.com\">Test Link</a></h1>" }
Example Response:
json { "data": { "id": 3, "action": "comment", "user": "288fdccc-399a-40a1-ac63-811bf62e6a18", "timestamp": "2023-09-06T02:23:40.740Z", "ip": "10.42.0.1", "useragent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36", "collection": "directusfiles", "item": "7247dda1-c386-4e7a-8121-7e9c1a42c15a", "comment": "<h1>TEST <p style=\"color:red\">HTML INJECTION</p> <a href=\"//evil.com\">Test Link</a></h1>", "origin": "https://directus.local", "revisions": [] } }
Example Result:
!Screenshot 2023-09-06 094536
Impact
With the introduction of session cookies this issue has become exploitable as a malicious script is now able to do authenticated actions on the current users behalf.
Other sources
Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which can be bypassed, making the application vulnerable to HTML Injection. This vulerability is fixed in 10.13.4 and 11.2.0.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54128?
CVE-2024-54128 is classified as a medium severity vulnerability due to its HTML Injection potential.
How do I fix CVE-2024-54128?
To fix CVE-2024-54128, upgrade to Directus version 11.2.2, 10.13.4, or 13.3.1, which remediate the vulnerability.
Which software versions are affected by CVE-2024-54128?
CVE-2024-54128 affects Directus versions between 10.10.0 and 10.13.4, 11.0.0-rc.1 and 11.2.2, and all versions prior to 13.3.1 of @directus/app.
What type of attack does CVE-2024-54128 enable?
CVE-2024-54128 enables attackers to perform HTML Injection attacks due to inadequate server-side validation.
Is client-side filtering sufficient to prevent vulnerabilities like CVE-2024-54128?
No, client-side filtering is not sufficient, as it can be bypassed, highlighting the need for server-side validation.