IoT & Hardware

Cross-Site Scripting (XSS)

HiveMQ MQTT broker - XSS Over MQTT

Stored XSS on the HiveMQ Broker management console An issue was discovered on HiveMQ MQTT Broker, The client id of any connected device is not sanitized for XSS in the admin console leading to stored…

5.4
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS44
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-13821
VENDORS
HiveMQ
PUBLIC EXPLOIT
None indexed
CWE
CWE-79
PRODUCT
HiveMQ MQTT Broker 4.3.2
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Stored XSS on the HiveMQ Broker management console

An issue was discovered on HiveMQ MQTT Broker, The client id of any connected device is not sanitized for XSS in the admin console leading to stored XSS.

Vulnerability details

Vulnerability details

CVE-2020-13821
CWE-79
Medium | 5.4

Stored XSS on the HiveMQ Broker management console An issue was discovered on HiveMQ MQTT Broker, The client id of any connected device is not sanitized for XSS in the admin console leading to stored XSS.

Auth:
Any authenticated user (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
DISCLOSURE

Disclosure timeline

2020-05-18 reported to the vendor

2020-08-25 Bug fixed and responsible disclosure after 90 days. .

Credits

Arun Magesh