Document Title: =============== Feeder.co RSS Feeder 5.2 Chrome - Persistent Software Vulnerability Release Date: ============= 2013-10-26 Vulnerability Laboratory ID (VL-ID): ==================================== 1119 Common Vulnerability Scoring System: ==================================== 3.8 Product & Service Introduction: =============================== Feeder.co (www.feeder.co) is the simplest and prettiest way to follow your favorite feeds and sites. Feeder supports most RSS and Atom feeds on the web. Get a simple overview of your RSS and Atom feeds in the toolbar. A simple and pretty way of keeping track of your latest RSS and Atom feeds. The best RSS Feed Reader extension for Chrome. - Instantaneously see when new posts are added to one of your RSS and Atom feeds - Easily subscribe to new RSS/Atom feeds by clicking the browser icon - Intuitively manage your feeds - Right click context-menus in popup-menu let you mark all as read, and other nifty shortcuts - Export your feeds so you can import them on another computer and/or keep them as backups for safekeeping - Customize your feeds by choosing how many posts to display, or changing the title - Organize your feeds using folders and sorting with drag and drop - Choose between three different themes: Dark, Mint or Light - Everything is contained within the browser so no other third-party sites are needed - Notifications when feeds have been updated. Enable globally or on select feeds - Supports both RSS and Atom feeds - See when a page has any RSS or Atom feeds to subscribe to (Copy of the Vendor Product Homepage: http://feeder.co ) Abstract Advisory Information: ============================== The Vulnerability Laboratory Research Team discovered a persistent web vulnerability in the Feeder.co RSS Feeds Chrome Addon. Vulnerability Disclosure Timeline: ================================== 2013-10-26: Researcher Notification & Coordination (Ateeq Khan) Discovery Status: ================= Published Affected Product(s): ==================== Feeder.co Product: RSS Feeder - Chrome Browser Addon 5.2 Exploitation Technique: ======================= Remote Severity Level: =============== Medium Technical Details & Description: ================================ A remote script code execution vulnerability has been detected in the official feeder.co RSS browser extension application. The vulnerability allows remote attackers to manipulate via POST method web-application to browser requests (persistent). The vulnerability affects the main feed input field and since the application is not performing input sanatization properly, it is possible to inject persistent script code within the affected folder name input field which then directly gets executed when the victim tries to delete the malicious entry. It is possible to inject malicious script code in the folder `Name` field parameter of the feeds while adding a new entry. The code execution happens when a user tries to delete the injected entries. the affected sourcecode with injected payload is given below for your reference: