CVE-2017-5631
MEDIUM NUCLEICaseAware - Reflected Cross-Site Scripting via Login Page User Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-5631. PoCs published by justpentest. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in CaseAware's login.php via the 'usr' parameter. The PoC shows how an attacker can inject malicious JavaScript into the query string, which executes when the victim clicks the crafted link.
Description
An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is transmitted in the login.php query string.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in CaseAware's login.php via the 'usr' parameter. The PoC shows how an attacker can inject malicious JavaScript into the query string, which executes when the victim clicks the crafted link.
Nuclei Templates (1)
title="caseaware"
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N