目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2023-25292 PoC — Intermesh BV Group Office 跨站脚本漏洞

来源
关联漏洞
标题: Intermesh BV Group Office 跨站脚本漏洞 (CVE-2023-25292)
Description:Intermesh BV Group Office是Intermesh BV开源的一个企业 CRM 和群件工具。 Intermesh BV Group Office 6.6.145版本存在安全漏洞。攻击者利用该漏洞通过GO_LANGUAGE cookie提升权限和获取敏感信息。
Description
Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive information via the GO_LANGUAGE cookie
介绍
# CVE-2023-25292
Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive information via the GO_LANGUAGE cookie

# Vulnerability Details
+ Product: Group Office Application
+ Version: 6.6.145
+ Vulnerability Type: Reflected XSS
+ Severity: Medium
+ CVSS v3.1 Score: 6.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

# Vulnerability Description
The application is vulnerable to a reflected XSS attack via the “GO_LANGUAGE” cookie that injects 
malicious JavaScript into the application's response. The malicious script is executed in the context of 
the affected website, allowing an attacker to steal sensitive information such as session cookies, 
personal information, etc.
The vulnerability exists in the cookie of the Group Office application. By sending a specially crafted 
cookie to the server, an attacker can inject malicious JavaScript code into the response, which is then 
executed in the context of the affected website. This can result in sensitive information being stolen 
from the user's browser, such as session cookies and personal information.

# Impact
This vulnerability allows an attacker to steal sensitive information from the affected website and its 
users, such as session cookies, personal information, and more. An attacker can also use this 
vulnerability to inject further malicious code into the affected website, compromising its functionality 
and potentially exposing sensitive information.

# Remediation for the vendor
+ Filter input data to prevent malicious payloads from being included in the response.
+ Use a Content Security Policy (CSP) to restrict the execution of untrusted JavaScript in the 
response.
+ Escape or encode all user input before including it in the response.

# Remediation for the end user
+ Upgrade to version 6.6.147 of the Group Office application.


# Steps to Reproduce
1. Go to the vulnerable instance of group-office.
2. Change the “GO_LANGUAGE” cookie with F12, to the following payload: 
```
ar'"()&%<zzz><ScRiPt>alert(911)</ScRiPt>
```
![image](https://user-images.githubusercontent.com/92050069/234384490-11209b6a-fd2a-42a6-8804-0eb5edac79a9.png)

3. Reload the page and then you will see that the payload is executed.
![image](https://user-images.githubusercontent.com/92050069/234384705-46fafd54-9496-4733-916d-5a55ee09002c.png)

# References
+ https://github.com/Intermesh/groupoffice/blob/master/CHANGELOG.md
+ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25292
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →