T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/qrcode.js:157- Finding
Arbitrary QR Code Content Is Disclosed to a Remote URL-Shortening Service
- Content
View full analysis
{ // API parameters const postData = querystring.stringify({ version: '2', url: longUrl }); const options = { hostname: 'www.dxmpay.com', port: 443, path: '/facilepaycenter/tinyurl/createurl', method: 'POST', headers: { 'Content-Type': 'application/x-www-form-urlencoded', 'Content-Length': Buffer.byteLength(postData) }, secureOptions: require('crypto').constants.SSL_OP_LEGACY_SERVER_CONNECT }; const req = https.request(options, (res) => { let result = ''; res.on('data', (chunk) => { result += chunk; }); res.on('end', () => { try { const jsonRes = JSON.parse(result); resolve(jsonRes); } catch (e) { resolve(result); } }); }); req.on('error', (e) => { reject(e); }); req.write(postData); req.end(); }); } ``` ```javascript const shortUrlResult = await createDxmShortUrl(text); if (shortUrlResult && shortUrlResult.content&&shortUrlResult.content.tinyurl) { text = "https://www."+shortUrlResult.content.tinyurl; } ``` ### Technical Analysis The QR generator submits every input string to `www.dxmpay.com` before generating the QR code locally. There is no check that the input is a URL, uses HTTPS, or belongs to the `www.dxmpay.com` domain. This behavior contradicts the restriction stated in `SKILL.md`, which claims that the short-link service only receives URLs beginning with `https://www.dxmpay.com/`. The implementation will instead transmit arbitrary QR content, including access tokens, private links, personal information, ...[truncated 962 chars]- Remediation
View remediation
