GHSA-ggwq-xc72-33r3
LGSL has a reflected XSS at /lgsl_files/lgsl_list.php
Details
# Reflected XSS at /lgsl_files/lgsl_list.php
**Description:**
Vulnerability: A reflected XSS vulnerability exists in the `Referer` HTTP header of [LGSL v6.2.1](https://github.com/tltneon/lgsl/releases/tag/v6.2.1). The vulnerability allows attackers to inject arbitrary JavaScript code, which is reflected in the HTML response without proper sanitization. When crafted malicious input is provided in the `Referer` header, it is echoed back into an HTML attribute in the application’s response.
The vulnerability is present at [Line 20-24](https://github.com/tltneon/lgsl/blob/master/lgsl_files/lgsl_list.php#L20-L24) ```php $uri = $_SERVER['REQUEST_URI'];
if ($lgsl_config['preloader']) { $uri = $_SERVER['HTTP_REFERER']; } ```
**Proof of Concept:** 1. Capture a request to the path `/lgsl_files/lgsl_list.php`. 2. Inject the following payload into the Referer header: `test'><script>alert(1)</script><`. 3. Send the request. 4. The XSS payload is triggered when reloading.  
**Impact:**
Execution of Malicious Code
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for tltneon/lgsl (composer). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/tltneon/lgsl/security/advisories/GHSA-ggwq-xc72-33r3[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-56517[ADVISORY]
- https://github.com/tltneon/lgsl/commit/7ecb839df9358d21f64cdbff5b2536af25a77de1[WEB]
- https://github.com/tltneon/lgsl[PACKAGE]
- https://github.com/tltneon/lgsl/blob/master/lgsl_files/lgsl_list.php#L20-L24[WEB]