VDB
Sign up
MEDIUM

GHSA-ggwq-xc72-33r3

LGSL has a reflected XSS at /lgsl_files/lgsl_list.php

Details

# Reflected XSS at /lgsl_files/lgsl_list.php

**Description:**

Vulnerability: A reflected XSS vulnerability exists in the `Referer` HTTP header of [LGSL v6.2.1](https://github.com/tltneon/lgsl/releases/tag/v6.2.1). The vulnerability allows attackers to inject arbitrary JavaScript code, which is reflected in the HTML response without proper sanitization. When crafted malicious input is provided in the `Referer` header, it is echoed back into an HTML attribute in the application’s response.

The vulnerability is present at [Line 20-24](https://github.com/tltneon/lgsl/blob/master/lgsl_files/lgsl_list.php#L20-L24) ```php $uri = $_SERVER['REQUEST_URI'];

if ($lgsl_config['preloader']) { $uri = $_SERVER['HTTP_REFERER']; } ```

**Proof of Concept:** 1. Capture a request to the path `/lgsl_files/lgsl_list.php`. 2. Inject the following payload into the Referer header: `test'><script>alert(1)</script><`. 3. Send the request. 4. The XSS payload is triggered when reloading. ![image](https://github.com/user-attachments/assets/467a6c60-db45-4520-9918-59dff819b384) ![image](https://github.com/user-attachments/assets/c537c59e-38c2-47f0-97d8-54ee1b2018b8)

**Impact:**

Execution of Malicious Code

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/tltneon/lgsl
Introduced in: 0

No fixed version published yet for tltneon/lgsl (composer). Pin to a known-safe version or switch to an alternative.

References