kiteworks by Accellion - Reflected XSS

2017.07.11
Credit: bRpsd
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ Product -> kiteworks by Accellion - Reflected XSS Date Found -> July 11, 2017 Author -> bRpsd Contact via skype => vegnox Kiteworks Website -> https://www.kiteworks.com/ Vendor Website -> http://www.accellion.com/solutions Tested on -> ngix, on all current versions of kiteworks. Shodan Dork -> https://www.shodan.io/search?query=Set-Cookie%3A+idpSAMLSessionID Shodan Total Results -> 622 @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ ############# |DESCRIPTION| ############# "Kiteworks Enables secure access and sharing of enterprise content from any device, including laptop, desktop or mobile. kiteworks enhances business productivity while ensuring data security and compliance.." Vulnerability: Reflected Cross Site Scripting File Path: http://target/idp/module.php/accellion/loginuserpass.php Vul Parameter: code Using a valid [AuthState] key which is normally generated by the server , you can reflect html using the [code] parameter. Example : http://172.1.2.3/idp/module.php/accellion/loginuserpass.php?AuthState=_b13beca9492737139e3ec622fc0306a520b3082948&code=</><h1>Reflected XSS here. -


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2017, cxsecurity.com

 

Back to Top