Where
AND
-Infinity
0
Severity
7.7
Path Traversal
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Summary By abusing the mail notification template it is possible to read arbitrary operating system files.

Details The dataUrl function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path, reads the file's content, and converts it into a Base64-encoded string. By embedding this function within a system notification template, the attacker can exfiltrate the Base64-encoded file content through a triggered system email notification. Once the email is received, the Base64 payload can be decoded, allowing the attacker to read arbitrary files on the server.

Requirements: write permissions to system notification templates ability to trigger a corresponding system email

PoC 1) Modify a template to contain the following twig template string: twig {{ dataUrl('/var/www/web/.env') }} 2) Trigger the corresponding notification email (e.g. by resetting a password) 3) Receive the email and decode the base64 string

Mail received: !Bildschirmfoto 2024-09-05 um 16 20 41

Decoded string: !Bildschirmfoto 2024-09-05 um 16 28 24

Impact 1) Exposure of Sensitive Information: Arbitrary file read can lead to the exposure of sensitive data such as configuration files (e.g., /etc/passwd, .env, config.php), which may contain credentials, API keys, or database passwords. This can provide the attacker with further access to the system or connected services.

2) Privilege Escalation: If the attacker is able to read files that contain privileged information, such as credentials for other systems or applications, they may be able to escalate their privileges beyond what the web admin role originally allowed, potentially gaining full control over the server or other related systems.

3) Server Compromise: Access to files like SSH keys, private certificates, or system configuration files can lead to the complete compromise of the underlying server. With this information, an attacker could remotely log in to the server or impersonate it in secure communications.

4) Exfiltration of User Data: The ability to read arbitrary files may allow an attacker to access user data, such as stored passwords, session tokens, or private information (like uploaded files or logs), leading to a breach of confidentiality and violating privacy regulations (e.g., GDPR).

1 / 2
Source: GitHub
First published (updated )
Severity
5.5
XSS
AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

Summary Multiple Stored XSS can be triggered by the breadcrumb list and title fields with user input.

Details 1. In the /admin/categories page, category title isn't sanitized and triggered xss. 2. In the category edit page under the /admin/categories/, category title in breadcrumb list isn't sanitized and triggered xss. 3. In the /admin/entries page, entry title isn't sanitized and triggered xss. 4. In the entry edit page under the /admin/entries/, entry title in breadcrumb list isn't sanitized and triggered xss. 5. In the /admin/myaccount and pages under it, username or full name in breadcrumb list isn't sanitized and triggered xss.

Impact Malicious users can tamper with the control panel.

PoC 1. In the /admin/categories page, category title isn't sanitized and triggered xss. 1. Access to the Settings -> Categories ( /admin/settings/categories ) 2. Create new category group 3. Access to the Categories page ( /admin/categories/ ) 4. Push the New category button 5. Input the Title column : xss<script>alert('xss')</script> 6. Push the Create Category or Save button 7. Access to the Categories page again and it triggers xss !image !image !image

2. In the category edit page under the /admin/categories/, category title in breadcrumb list isn't sanitized and triggered xss. 1. Access to the Settings -> Categories ( /admin/settings/categories ) 2. Create new category group 3. Access to the Categories page ( /admin/categories/ ) 4. Push the New category button 5. Input the Title column : xss<script>alert('xss')</script> 6. Push the Create Category or Save button 7. Access to the Category edit page again and it triggers xss !image !image !image

3. In the /admin/entries page, entry title isn't sanitized and triggered xss. 1. Access to the Settings -> Entry Types ( /admin/settings/entry-types ) 2. Create new entry type 3. Access to the Settings -> Sections ( /admin/settings/sections ) 4. Create new section 5. Access to the Entries page ( /admin/entries ) 6. Push the New entry button 7. Input the Title column : xss<script>alert('xss')</script> 8. Push the Create entry or Save button 9. Access to the Entries page again and it triggers xss !image !image !image

4. In the entry edit page under the /admin/entries/, entry title in breadcrumb list isn't sanitized and triggered xss. 1. Access to the Settings -> Entry Types ( /admin/settings/entry-types ) 2. Create new entry type 3. Access to the Settings -> Sections ( /admin/settings/sections ) 4. Create new section 5. Access to the Entries page ( /admin/entries ) 6. Push the New entry button 7. Input the Title column : xss<script>alert('xss')</script> 8. Push the Create entry or Save button 9. Access to the Entriy edit page again and it triggers xss !image !image !image

5. In the /admin/myaccount and pages under it, username or full name in breadcrumb list isn't sanitized and triggered xss. 1. Access to the My Account Page ( /admin/myaccount ) 2. Input the Full Name column : xss<script>alert('xss')</script> 3. Push the the Save button 4. Access to the My Account page ( /admin/myaccount ) or pages under it ( /admin/myaccount/addresses , /admin/myaccount/preferences , etc.) and it triggers xss !image !image !image

1 / 2
Source: GitHub
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203