T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:511- Finding
Stored HTML Injection Through Unescaped CSV Content
- Content
View full analysis
$(basename "$file")
" >> "$outfile" local first=true while IFS= read -r line; do if $first; then echo "$(echo "$line" | sed 's/,/<\/th>" >> "$outfile" first=false else echo "$(echo "$line" | sed 's/,/<\/td>" >> "$outfile" fi done < "$file" ``` ### Technical Analysis The `to-html` command inserts the input filename and every line of the CSV file directly into an HTML document. The `sed` expressions only replace commas and add table tags; they do not encode HTML-sensitive characters such as `<`, `>`, `&`, `"`, or `'`. Consequently, an attacker-controlled CSV cell can terminate the generated `/g; s/^/ /; s/$/<\/th>/') /g; s/^/ /; s/$/<\/td>/') ` or ` ` element and introduce arbitrary HTML. Depending on the browser and payload, injected content can include scripts, event handlers, misleading forms, iframes, or elements that initiate external network requests. The implementation also does not use a standards-compliant CSV parser. Quoted fields, embedded commas, and multiline fields may therefore be processed incorrectly in addition to the security issue. ### Attack Path 1. An attacker creates or modifies a CSV file that contains an HTML payload in a header or data cell, such as an element with an event handler. 2. The attacker convinces a user to process the file with: ```bash scripts/script.sh to-html attacker.csv ``` 3. The command copies the malicious cell into `attacker.html` without HTML encoding. 4. The user opens the generated report in a web browser. 5. The browser interprets the injected value as active markup rather than text. 6. The payload can modify the report, display deceptive content, execute browser-side code ...[truncated 792 chars] - Remediation
View remediation
