MEDIUM 6.1 Maven

JavaScript execution via malicious molfiles (XSS)

GHSA-2pwh-52h7-7j84 · CVE-2024-0758

Published · Modified

Description

Impact

The viewer plugin implementation of <mol:molecule> renders molfile data directly inside a <script> tag without any escaping. Arbitrary JavaScript code can thus be executed in the client browser via crafted molfiles.

Patches

Patched in v0.3.0: Molfile data is now rendered as value of a hidden <input> tag and escaped via JSF's mechanisms.

Workarounds

No workaround available.

Ready to move

Start Securing

Free, no credit card | First findings in minutes