CVE-2025-68723: Axigen WebAdmin Stored XSS
Vulnerability Summary
Multiple input fields within the Axigen WebAdmin interface lack proper sanitization, allowing for the execution of malicious JavaScript. These vulnerabilities enable a low-privileged administrator (or an attacker leveraging Broken Access Control) to execute arbitrary code in the context of a high-privileged administrator, leading to full privilege escalation.
Affected Versions: < 10.6.26
For more info, see the Axigen Knowledge Base.
POC
I detected 3 different instances of Stored XSS:
- Logging > Local Services Log: Injecting a payload into a log file name. This one have limitations due to character length limit of a log file name.
- Security & Filtering > SSL Certificates: Injecting a payload into a
.pem certificate file.
- Services > Webmail > Listeners: Injecting a payload into the Certificate File name field.
Example Payload:
u+='&manage'+p+'=manage'+p);u+='&accessDumpData=accessDumpData&quick-add=Quick+Add&permType=manageServices&permAction=grant&servAction=grant';location.search=u">
Payload Explanation:
The payload you see above will grant all permissions to account named admin2.
Steps to Reproduce:
- Injection: Navigate to any of the affected components (e.g., Security & Filtering > SSL Certificates).
- Execution: Rename a log file or upload a certificate containing the malicious payload. (I've added a certificate file containing the 'Example Payload')
- Trigger: When a high-privileged administrator views the log list or clicks "View Usage" on the malicious certificate, the script executes.
Impact
- Privilege Escalation: A low-privileged admin can gain full system control by targeting a high-privileged admin and perform actions on behalf of other administrators.