PT-2026-83677 · Ash Admin · Ash Admin
CVSS v4.0
8.4
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ash admin versions 0.13.0 through 1.3.0
Description
A stored Cross-site Scripting (XSS) issue exists where attacker-supplied record content is executed as a script in an administrator's browser. The relationship typeahead components
AshAdmin.Components.Resource.RelationshipField and AshAdmin.Components.Resource.ManagedRelationshipSelectField highlight search terms by wrapping them in <b> tags and rendering the string using the Phoenix.HTML.raw/1 function. Since raw/1 disables output escaping, a malicious label stored in the label field can execute JavaScript when a matching record appears in the dropdown, allowing an attacker to gain the administrator's privileges.Recommendations
Update ash admin to version 1.3.1 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ash Admin