Swagger-UI is vulnerable to html injection

677 views
Skip to first unread message

Fallen apple

unread,
Nov 8, 2023, 10:11:33 AM11/8/23
to cBioPortal for Cancer Genomics Discussion Group
Hello,
This is fallenapple a security researcher. 

I found a security vulnerability in your assets 
Vulnerability 
Html injection in Swagger-UI 

Proof Of Concept
During the recon process, I found that this Link is vulnerable to HTML injection 
POC attachments:-
screen02.jpg
Fake Login page
POC payload:-

Regards,
fallenapple

Benjamin Gross

unread,
Nov 8, 2023, 10:58:39 AM11/8/23
to Fallen apple, cBioPortal for Cancer Genomics Discussion Group
Thank you for bringing this to our attention.  I have created an issue so that our engineers can address this:


Best,
-Benjamin

On Nov 7, 2023, at 1:34 AM, Fallen apple <muneebm...@gmail.com> wrote:

Hello,
This is fallenapple a security researcher. 

I found a security vulnerability in your assets 
Vulnerability 
Html injection in Swagger-UI 

Proof Of Concept
During the recon process, I found that this Link is vulnerable to HTML injection 
POC attachments:-
--
You received this message because you are subscribed to the Google Groups "cBioPortal for Cancer Genomics Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cbioportal+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/cbioportal/1b88beaa-70c2-405c-b237-39c6de3e91cdn%40googlegroups.com.
<screen02.jpg>

Reply all
Reply to author
Forward
0 new messages