CVE-2018-1321
HIGHApache Syncope 1.2.0-1.2.10 - Authenticated Remote Code Execution via XSLT
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-1321. PoCs published by Che-Chun Kuo.
AI-analyzed exploit summary This exploit demonstrates two vulnerabilities in Apache Syncope 2.0.7: RCE via XSLT injection in Reports/Templates and information disclosure via FIQL/ORDER BY sorting. The XSLT payloads show file read and command execution, while the FIQL/ORDER BY technique recovers sensitive data like security answers.
Description
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to file read, file write, and code execution.
Exploits (1)
This exploit demonstrates two vulnerabilities in Apache Syncope 2.0.7: RCE via XSLT injection in Reports/Templates and information disclosure via FIQL/ORDER BY sorting. The XSLT payloads show file read and command execution, while the FIQL/ORDER BY technique recovers sensitive data like security answers.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H