PT-2026-64028 · Unknown · Fathom Lite
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Fathom Lite versions prior to 1.3.2
Description
A stored cross-site scripting issue exists in the analytics collection endpoint. Unauthenticated attackers can inject a
javascript: URI into the Top Pages dashboard by sending a crafted hostname and pathname to the /collect endpoint. This occurs because the parseHostname() and parsePathname() functions do not perform URI scheme validation. Consequently, a javascript: hostname and a newline-prefixed pathname can be stored and subsequently rendered as an anchor href in the authenticated dashboard without sanitization. This can lead to session hijacking and full account takeover if an operator clicks the poisoned entry.Recommendations
Update Fathom Lite to version 1.3.2 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fathom Lite