[FD] Evolution Script CMS v5.3 – Cross Site Scripting Vulnerability

Document Title: =============== Evolution Script CMS v5.3 – Cross Site Scripting Vulnerability References (Source): ==================== http://ift.tt/2qVirbh Release Date: ============= 2017-06-07 Vulnerability Laboratory ID (VL-ID): ==================================== 2075 Common Vulnerability Scoring System: ==================================== 3.3 Vulnerability Class: ==================== Cross Site Scripting – Non Persistent Current Estimated Price: ======================== 500€ – 1.000€ Product & Service Introduction: =============================== Developed with a new improved and powerful core. Handy User interface to manage your business. Maximum security for you and your members. (Copy of the Homepage: http://ift.tt/29eR8DR ) Abstract Advisory Information: ============================== The vulnerability laboratory core research team discovered a client-side cross site scripting vulnerability in the official Evolution Script v5.3 Content Management System. Vulnerability Disclosure Timeline: ================================== 2017-06-07: Public Disclosure (Vulnerability Laboratory) Discovery Status: ================= Published Affected Product(s): ==================== Evolution Script S.A.C. Product: Evolution Script – Content Management System (Web-Application) 5.3 Exploitation Technique: ======================= Remote Severity Level: =============== Medium Technical Details & Description: ================================ A client-side cross site scripting vulnerability has been discovered in the official Evolution Script v5.3 Content Management System. The issue allows remote attackers to inject script code with client-side attack vector to compromise browser to application requests. The cross site vulnerability is located in the `status` parameter of the `Ticket Support` module. Remote attackers are able to inject own malicious script codes via GET method request. The attack vector is non-persistent and the request method to inject is GET. The vulnerability affects the support and administrator role in the ticket support module. The security risk of the vulnerability is estimated as medium with a cvss (common vulnerability scoring system) count of 3.2. Exploitation of the cross site vulnerability requires no privileged web-application user account and low user interaction. Successful exploitation results in session hijacking, non-persistent phishings attacks, non-persistent external redirect and malware loads or non-persistent manipulation of affected and connected module context. Request Method(s): [+] GET Vulnerable Module(s): [+] Support Tickets Vulnerable Parameter(s): [+] status Affected Role(s): [+] Support [+] Admin Proof of Concept (PoC): ======================= The client-side cross site scripting vulnerability can be exploited by remote attackers without user account and with low user interaction. For security demonstration or to reproduce the vulnerability follow the provided information and steps below to continue. PoC: Vulnerability http://ift.tt/2qVkQ5U SITE SCRIPTING VULNERABILITY!] PoC: Exploitation PoC: Vulnerable Source (status)
http://evil.source http://evil.source http://evil.source http://evil.source http://evil.source http://evil.source http://evil.source Records not found

Source: Gmail -> IFTTT-> Blogger

from Blogger http://ift.tt/2sjIa1E
via IFTTT

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s