Horizon Alert
Summary of the vulnerability and why it matters
This advisory details two combined code flaws in the SkillTree micro-learning platform that can be exploited through multiple paths, potentially allowing attackers to execute code in administrators' browsers. The main concern is confirming relevance and exposure.
- A security flaw in SkillTree allows code execution.
- Admins viewing quiz results could be impacted.
- Confirm if SkillTree is used and assess exposure.
Attack Path
How an attacker could exploit the issue
An attacker can register for an account on the SkillTree platform and inject malicious code into their profile fields. This code is then rendered in a vulnerable way when an administrator views the Quiz Runs page. The vulnerability can lead to arbitrary code execution, remote script loading, or cross-site request forgery token theft in the administrator's browser.
- Attacker registers an account.
- Admin views Quiz Runs page.
- Arbitrary code execution.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an attacker to execute arbitrary code in an administrator's browser when they access the Quiz Runs page. Supported conditions include an attacker self-registering an account and then triggering the vulnerability when an administrator views quiz results. The impact can escalate from basic cross-site scripting to remote script loading or cross-site request forgery token theft, potentially allowing unauthorized actions or data exfiltration.
- Administrator browser could be compromised.
- Malicious script injected via registration fields.
- Arbitrary code execution and data theft.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability affects the SkillTree gamification platform, likely impacting teams responsible for application development and infrastructure. The initial step is to identify all instances of SkillTree, determine their business criticality and network exposure, and locate the accountable owner to plan remediation.
- Application owners and platform teams should own the issue.
- Verify SkillTree deployment and administrative access points.
- Plan remediation based on risk and vendor coordination.