Advertisement






Kaa IoT Platform 1.2.0 Cross Site Scripting

CVE Category Price Severity
CVE-2020-26701 CWE-79 $5000 High
Author Risk Exploitation Type Date
Unknown High Remote 2020-11-16
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2020110131

Below is a copy:

Kaa IoT Platform 1.2.0 Cross Site Scripting
#Exploit Title: Kaa IoT Platform 1.2.0 Cross Site Scripting (XSS)
Vulnerability
#Date: 2020-10-01
#Exploit Author: Mufaddal Masalawala
#Vendor Homepage: https://www.kaaproject.org/
#Software Link: https://cloud.kaaiot.com/
#Version: 1.2.0
#Tested on: Kali Linux 2020.3
#CVE: CVE-2020-26701
#Proof Of Concept:
Cross-site scripting (XSS) vulnerability in Dashboards section in Kaa IoT
Platform v1.2.0 allows remote attackers to inject malicious web scripts or
HTML Injection payloads via the Description parameter.
To exploit this vulnerability:

   1. Open Firefox browser, login to the cloud.kaaiot.com and access the
   dashboard
   2. Go to 'Solutions' module, select any one solution(create if not
   present) and click on it.
   3. Now in the Dashboards module, edit the Dashboard.
   4. in Description, enter the payload <img src="x"
   onerror="alert(window.location)" /> and click 'Update'.
   5. Open that Dashboard and you'll receive an alert executing user
   supplied script in the browser.

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum