TOTVS Fluig Platform mobileredir openApp.jsp cross site scripting

CVE-2023-6275
6.1MEDIUM

Key Information

Vendor
TOTVS
Status
Fluig Platform
Vendor
CVE Published:
24 November 2023

Badges

👾 Exploit Exists🔴 Public PoC

Summary

A vulnerability was found in TOTVS Fluig Platform 1.6.x/1.7.x/1.8.0/1.8.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /mobileredir/openApp.jsp of the component mobileredir. The manipulation of the argument redirectUrl/user with the input "><script>alert(document.domain)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.7.1-231128, 1.8.0-231127 and 1.8.1-231127 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-246104.

Affected Version(s)

Fluig Platform = 1.6.x

Fluig Platform = 1.7.x

Fluig Platform = 1.8.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit exists.

  • Vulnerability Reserved.

  • Vulnerability published.

Collectors

NVD DatabaseMitre Database1 Proof of Concept(s)

Credit

erickfernandox (VulDB User)
.