From 290aaefa3949217de1eeb6aa07bc557c1d60e918 Mon Sep 17 00:00:00 2001
From: PikPikcU <60111811+pikpikcu@users.noreply.github.com>
Date: Mon, 8 Mar 2021 05:43:56 +0000
Subject: [PATCH] Create CVE-2020-12258.yaml
---
cves/2020/CVE-2020-12258.yaml | 26 ++++++++++++++++++++++++++
1 file changed, 26 insertions(+)
create mode 100644 cves/2020/CVE-2020-12258.yaml
diff --git a/cves/2020/CVE-2020-12258.yaml b/cves/2020/CVE-2020-12258.yaml
new file mode 100644
index 0000000000..094fac6275
--- /dev/null
+++ b/cves/2020/CVE-2020-12258.yaml
@@ -0,0 +1,26 @@
+id: CVE-2020-12258
+
+info:
+ name: rConfig 3.9.4 XSS
+ author: pikpikcu
+ severity: medium
+ reference: https://nvd.nist.gov/vuln/detail/CVE-2020-12258
+ tags: cve,cve2020,rconfig,xss
+
+requests:
+ - method: GET
+ path:
+ - '{{BaseURL}}/configDevice.php?rid=">'
+
+ matchers-condition: and
+ matchers:
+
+ - type: word
+ words:
+ - ""
+ part: body
+ condition: and
+
+ - type: status
+ status:
+ - 200