Description
Concatenating or formatting user input into an XPath expression can let an attacker bypass conditions or query unintended XML nodes.
Potential impact
- Authentication or authorization checks may be bypassed.
- Sensitive information may be exposed from XML data.
Remediation
- Keep XPath expressions constant. Bind values as variables if the API supports it; otherwise, select nodes with a fixed path and compare values in application code.
- Validate input format and length with an allow-list, and check access to the nodes you return.
Examples
These excerpts assume goxpath, the XML document doc and request r are available.
Before
go
expr := "//user[@id='" + r.FormValue("id") + "']"
goxpath.MustExec(expr, doc)
After
go
expr := "/root/user"
goxpath.MustExec(expr, doc)
Explanation:
- Before: Input becomes part of XPath syntax and can change the condition.
- After: The expression queries a fixed path; it does not implement variable binding or an ID filter. Implement the required user selection and authorization before returning results.