Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-41502 PoC — Jetimob Plataforma Imobiliaria 安全漏洞

Source
Associated Vulnerability
Title:Jetimob Plataforma Imobiliaria 安全漏洞 (CVE-2024-41502)
Description:Jetimob Plataforma Imobiliaria是巴西的一个房地产平台。 Jetimob Plataforma Imobiliaria 20240627-0版本存在安全漏洞,该漏洞源于Pessoas部分的Observaces字段存在跨站脚本漏洞,可能导致注入任意Web脚本或HTML。
Readme
# CVE-2024-41502

- **CVE:** CVE-2024-41502
- **Software:** Jetimob Plataforma Imobiliaria (CRM/ERP/CMS)
- **Version:** 20240627-0
- **Vulnerability:** Stored Cross-Site Scripting (XSS)
- **Description:** Stored XSS via the form field "Observações" in the "Pessoas" section when creating or editing either a legal or a natural person.  It is then executed whenever the person's profile containing the payload is loaded.
- **Payload**: `<img src=x onerror=alert(document.cookie)>`

![](img/1.png)  

![](img/2.png)  

![](img/3.png)  

![](img/4.png)
File Snapshot

[4.0K] /data/pocs/5d4fc0e0c364a708a34f99db0ce6620c099a93b7 ├── [4.0K] img │   ├── [120K] 1.png │   ├── [137K] 2.png │   ├── [ 99K] 3.png │   └── [ 94K] 4.png └── [ 552] README.md 1 directory, 5 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.