Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-41504 PoC — Jetimob Plataforma Imobiliaria 安全漏洞

Source
Associated Vulnerability
Title:Jetimob Plataforma Imobiliaria 安全漏洞 (CVE-2024-41504)
Description:Jetimob Plataforma Imobiliaria是巴西Jetimob公司的一个房地产平台。 Jetimob Plataforma Imobiliaria 20240627-0版本存在安全漏洞,该漏洞源于Oportunidades部分的Descrico字段存在跨站脚本漏洞,可能导致注入任意Web脚本或HTML。
Readme
# CVE-2024-41504

- **CVE:** CVE-2024-41504
- **Software:** Jetimob Plataforma Imobiliaria (CRM/ERP/CMS)
- **Version:** 20240627-0
- **Vulnerability:** Stored Cross-Site Scripting (XSS)
- **Description:** In the "Oportunidades" section of the application when creating or editing an "Atividade" (activity), the form field "Descrição" allows injection of JavaScript code. It is then executed whenever the activity containing the payload is loaded.
- **Payload:** `<img src=x onerror=alert(document.cookie)>`

![](img/1.png)  

![](img/2.png)
File Snapshot

[4.0K] /data/pocs/f32f8b83133660f25c4f3278971e1c6b642f99fd ├── [4.0K] img │   ├── [171K] 1.png │   └── [101K] 2.png └── [ 543] README.md 1 directory, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.