Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-14294 PoC — Secudos Qiata FTA 跨站脚本漏洞

Source
Associated Vulnerability
Title:Secudos Qiata FTA 跨站脚本漏洞 (CVE-2020-14294)
Description:secudos qiata fta是德国SECUDOS的一个安全文件传输软件。该软件适用于团队之间的文件操作并遵守 GDPR 协议保护数据安全。 Secudos Qiata FTA 1.70.19版本存在安全漏洞。该漏洞源于评论特性允许在读取、传输评论或全局通知板时执行持久的跨站访问。
Description
This repository holds the advisory of the CVE-2020-14294
Readme
# CVE-2020-14294

This vulnerablity was discovered and disclosed by me. This repository will hold the advisory.

This repository is only for educational purposes.

# Links

- [Advisory SYSS-2020-024](https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2020-024.txt)
- [Detailed writeup](https://hesec.de/posts/cve-2020-14293a14294/)
- [SySS Blog entry](https://www.syss.de/pentest-blog/syss-2020-024-und-syss-2020-025-zwei-schwachstellen-in-file-transfer-loesung-von-qiata)
- [Vendor notice](https://www.secudos.de/news-und-events/aktuelle-news/sicherheitsluecken-in-domos-und-qiata-2-0-behoben)
- [MITRE Entry](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14294)
- [NVD Entry](https://nvd.nist.gov/vuln/detail/CVE-2020-14294)
File Snapshot

[4.0K] /data/pocs/296f66946bd9b2ae527e854b7f19d3eebcdbcda2 ├── [4.0K] advisory │   └── [4.8K] SYSS-2020-024.txt.asc └── [ 756] README.md 1 directory, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.