Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-54160. PoCs published by Jflye.
AI-analyzed exploit summary This PoC demonstrates a stored XSS and HTML injection vulnerability in OpenSearch's 'reports' plugin (version 2.18.0 and earlier). It exploits unsanitized input in report headers/footers to inject an iframe fetching a keylogger, proving arbitrary JavaScript execution.
Description
dashboards-reporting (aka Dashboards Reports) before 2.19.0.0, as shipped in OpenSearch before 2.19, allows XSS because Markdown is not sanitized when previewing a header or footer.
Exploits (1)
This PoC demonstrates a stored XSS and HTML injection vulnerability in OpenSearch's 'reports' plugin (version 2.18.0 and earlier). It exploits unsanitized input in report headers/footers to inject an iframe fetching a keylogger, proving arbitrary JavaScript execution.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N