DMCA.com Improper Access Control / Cross Site Scripting

2022.01.12
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

Publisher: Joel Aviad Ossi Company: Pentest <https://websec.nl>company WebSec B.V. Vulnerabilities: Improper access Control, Stored Cross-Site Scripting and Improper Input Validation Description: It is possible to inject javascript code into any DMCA account and takeover the API Token in order to read support messages (It is also possible to inject such code into the support ticket in order to target administrators) Additionally it is possible to bypass any website domain verification and issue valid DMCA Protection certificates for any domain name. Writeup: https://websec.nl/blog/606ecfec2f798a048269340e/dmcacom%20hack%20full%20disclosure%20with%20proof-of-concept Security Risk: Critical


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2022, cxsecurity.com

 

Back to Top