Skip to content

alemusix/CVE-2024-41640

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

8 Commits
 
 
 
 

Repository files navigation

Description

AML Surety Eco up to version 3.5 is affected by an un-authenticated reflected cross-site scripting.

The target web application handles error in a dedicated error page (accessible without any authentication) containing a URL parameter that is not sanitizing user input. The provided parameter value is reflected off the web application causing malicious payloads to execute JavaScript code on the victim’s browser.

Risk

Affected Resources

  • Version: up to AML Surety Eco v3.5
  • https://<application-baseurl>/Surety3Eco/AppError.aspx

The vulnerable parameter:

  • id

Evidence

It is possible to inject a JavaScript payload in the id URL parameter

image_1

Attacker can provide the URL with JavaScript payload to a victim that upon opening in the browser results in the execution of JavaScript code.

image_2

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published