Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-31537 PoC — SIS Informatik SIS SIS-REWE Go 跨站脚本漏洞

Source
Associated Vulnerability
Title:SIS Informatik SIS SIS-REWE Go 跨站脚本漏洞 (CVE-2021-31537)
Description:SIS Informatik SIS-REWE Go是奥地利SIS Informatik公司的一个应用程序。一款适用于公司会计的自适应,独立于分支机构的会计软件,可为工业,贸易公司,服务提供商和当局提供完善会计的一切。 SIS SIS-REWE Go 7.7 SP17版本之前存在跨站脚本漏洞。攻击者可以利用该漏洞获取敏感信息。
Description
SIS Informatik REWE GO SP17 before 7.7 contains a cross-site scripting vulnerability via rewe/prod/web/index.php (affected parameters are config, version, win, db, pwd, and user) and /rewe/prod/web/rewe_go_check.php (version and all other parameters).
File Snapshot

id: CVE-2021-31537 info: name: SIS Informatik REWE GO SP17 <7.7 - Cross-Site Scripting author: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.