-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

# Security Advisory

ARA-2020-002: Stored XSS in drive function

## Affected Product(s) and Environment(s)

Product: TeamBeam (Skalio GmbH) Version?
Environments: All browsers and operating systems

## Security Risk

Severity: High
Vulnerability Type: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)
CVSS v3: 5.4
## Impact
Confidentiality: Low
Integrity: Low
Availability: None
## Exploitability
Access Vector: Network
Access Complexity: Low
Privileges Required: Low
User Interaction: Required
## Scope
Scope: Changed


## Remediation Level
Currently unavailable, awaiting manufacturer's response.


## Timeline
2020-05-13: Initial Vendor contact
2020-05-28: Vendor issues a fix


## Description Summary
The Drive functionality of TeamBeam is vulnerable to a Cross-site Scripting attack. Additionally to that vulnerability the entries to the address book and mailing list names are also vulnerable to Cross-site Scripting attacks but due to the nature of these functions the impact is limited to the scope of the current user.


## Product Introduction:
TeamBeam is a scaleable, flexible solution for secure business data exchange that is designed to meet your individual demands. [TeamBeam website](https://www.teambeam.de/)


## Technical Description
The Drive functionality of TeamBeam allows a malicious user to create a folder with an arbitrary name. The foldername is not encoded during the output, which leads to a XSS vulnerability. The vulnerability is triggered every time the folder name is displayed. To gain additional priviledges the attacker could invite an admin account to the folder. If the admin accesses this folder, the malicious script code would be executed in the context of the admin user. This can allow the malicious user to create an admin account or change the privileges of his account.
The XSS in the entries of the addess book and in the mailing list name are limited to the scope of the user.


### Proof of Concept (PoC)
A malicious user can create a folder within the drive with an abitrary name. By creating a folder with the name  "<svg onload=alert('XSS')>" the malicious user is able to execute JavaScript code within the TeamBeam application.
The PoC above also works for the XSS in the address book entries and the mailing list name.


## Solution
The foldername needs to be encoded to HTML entities prior to embedding into the webpage. Additionally a validation of folder names is advised.


## References
[aramido responsible disclosure 
policy](https://aramido.de/blog/Sicherheitshinweise)


## Author
Tristan Wagner, aramido GmbH
E-mail: tristan.wagner@aramido.de
PGP-Key: https://aramido.de/tristan.wagner.asc
PGP-Fingerprint: 260A 1CBA 9472 6075 F05D DD11 6BF3 FEE3 AAE1 632A


## Disclaimer
The information provided in this advisory is provided "as is" without
any warranty. Details of this security advisory may be updated in order
to provide as accurate information as possible. The latest version of
this security advisory is available on the aramido web site. aramido
GmbH disclaims all warranties, either expressed or implied, including
the warranties of merchantability and capability for a particular
purpose. aramido GmbH or its suppliers are not liable in any case of
damage, including direct, indirect, incidental, consequential loss of
business profits or special damages, even if aramido GmbH or its
suppliers have been advised of the possibility of such damages. Some
states do not allow the exclusion or limitation of liability for
consequential or incidental damages so the foregoing limitation may not
apply. We do not approve or encourage anybody to break any vendor
licenses, policies, deface websites, hack into databases or trade with
fraud/stolen material.


## Copyright
CC-BY-4.0
http://creativecommons.org/licenses/by/4.0/

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE6GMZO9SOu//020sWLnuJprJNuOYFAl8FdEcACgkQLnuJprJN
uOabhw//WWoK6Q5/Z8/rWeERSxWYfBQpOwePpqvxdSgna9U2/Rcur/iuPhD8cxtf
N/wiv3K/pOguM9lx3jC0FypQcMejH+nqZ1hJRHOPKGjWPyFLz2dOGCK6xBB+PEB6
62rRCOT8mu47GHQRfkEICoS6nAnEdC6j+RwxcfpOYg/Hbh6QvfR717LXRPhzt3AB
Nn1fDhWig9plu2kahCQLJbpULdZvfCMa2MeB33r/cHVbCFkC1P6OVh9Y/MG89nEg
x9JHp9tdZG+JkZkwj7V+MTx4gofLEjam9Zv6EDwF5ITAQuBgx8X4HkYYOajXNues
d3CkRccSMfnnuqzi4U7Aaflzi6pbp8oCN9PUOJ1kxmpe9F+5kfRtPQZ5ljT5hZFS
twy1DpIDD4wi3C2yRPFx7sel2xANxSxWTqpZ2qaQ1FxxPUvaoubCvIanZSqjnuHz
nfua9kllvRI52Tu1VwhlGjAwFQdir4mQpgZasWD19xapUjmgQMIGe/6WYXd1d/v1
XbLVLvqcJRBqAf22AYiCpGB49nJhT85jvxTyQ8zm5H5KF5o1SX2FmBHZS4MuhDpu
esQsSgEobecEuSIgahKfDDCdhJv5jeBlugYn120aKPTyF8iiqg68CNLtMtYj7rtR
SjZr6dcJ2wMXf94cpugqhBkhUFFmGgGrRlCMAiVxNfzA+cJlvOk=
=vnN/
-----END PGP SIGNATURE-----
