THREAT OPS › Threat News › [GHSA] GHSA-c7hr-448w-65px (high) — MeshCentral has unsanitized data fields
[GHSA] GHSA-c7hr-448w-65px (high) — MeshCentral has unsanitized data fields
GHSA-c7hr-448w-65px Severity: high CVE: None
MeshCentral has unsanitized data fields
### Description
A rogue or compromised MeshAgent can inject arbitrary HTML/JavaScript via the osdesc (OS description) field in its coreinfo message. The server stores this value with zero HTML sanitization (meshagent.js:1903 only checks typeof == 'string'). When an admin views the device details panel, the valu
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- https://evil.com/steal?\url
Original source: https://github.com/advisories/GHSA-c7hr-448w-65px