CyberRota Analysis
AI-GeneratedMongoose versions prior to 7.22 are vulnerable to reflected cross-site scripting due to improper handling of percent-encoded request paths, which allows remote attackers to inject malicious scripts into web pages served by the embedded web server. This vulnerability can lead to session data exposure or unauthorized actions on behalf of users who visit the crafted URL. Organizations using Mongoose in their applications should prioritize upgrading to version 7.22 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it. The mg_http_serve_dir() and listdir() path in src/http.c places the decoded request URI into the title and h1 elements without HTML entity encoding. The resulting reflected cross-site scripting executes in the Mongoose origin and can expose session data or perform actions as the victim. This issue is fixed in version 7.22.