Stored Cross-Site Scripting in Moderator Toolbox by Reddit
CVE-2016-20098
5.1MEDIUM
What is CVE-2016-20098?
The Moderator Toolbox for Reddit prior to version 4.0.14 contains a serious vulnerability that opens the door to stored cross-site scripting attacks. Specifically, the issue lies within the removalreasons module, which inadequately handles input by failing to properly encode HTML when displaying subreddit toolbox wiki fields. This oversight allows malicious actors, who have the ability to edit the toolbox wiki page, to inject harmful JavaScript into critical fields. These scripts can subsequently execute within the context of a moderator's session, posing a significant threat to user accounts and the integrity of the Reddit platform.
Affected Version(s)
reddit-moderator-toolbox 0 < 4.0.14
reddit-moderator-toolbox 4.0.14
