HomeSecurityVulnerability in popular parental control app Canopy

Vulnerability in popular parental control app Canopy

A vulnerability in the Canopy parental control app allows attackers to inject JavaScript into the parent portal and gain access to all the features a parent would have with their child's device.

Canopy

See also: Vulnerability in VMware vCenter is still exploitable

A researcher at cybersecurity firm Tripwire discovered a vulnerability in the parental control app Canopy. Craig Young told ZDNet that he had learned about Canopy from his child's school and was curious to check out the app's cybersecurity capabilities.

He further investigated the application and realized that the URL in a parental control request was not being filtered properly. He found that a completely external user could inject this XSS with a single unknown numeric ID value, allowing an attacker to add JavaScript code to the parent portal for each Canopy account.

The JavaScript could then be used to do anything from cryptocurrency mining to browser exploits targeting parents. The JavaScript could also be used to extract data related to customer accounts – including location data from tracked devices. The data could be sold for a variety of undesirable purposes, Young added.

See also: Millions of HP OMEN PCs affected by a serious vulnerability

An attacker would have full access to the parent portal and all the features a parent has for monitoring and controlling children's devices, and Young said it appears an attacker could do this en masse across all of Canopy's customers.

Young contacted Canopy but said they were not very responsive, claiming that the vulnerability has been patched. But the researcher said the patch doesn't address the entire issue and only makes it so that a child would theoretically no longer be able to attack their parents with the explanation text. But the child could still attack the parent account using the address of a blocked website, as the cross site scripting vector and a third party could do that, Young said.

Canopy offers a wealth of services, including a cross-platform parental control app that allows parents to monitor and restrict how their children use a device.

Examining how the application works, Young discovered that the Canopy system fails to sanitize user-inputs leading to cross-site scripting, which allows attackers to embed an attack payload within an exception request.

Young noted that this type of breach is “noisy,” meaning a parent must interact with the malicious request and may recognize the attack in progress.

See also: Microsoft has fixed a vulnerability in Azure Container Instances

Ray Kelly, principal security engineer at NTT Application Security, said developers are still careless about accepting untrusted and unfiltered information from users. When asked how Canopy can fix the problem, Young said Canopy needs to sanitize all user-input values.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS