Record summary

CVE-2021-31537 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

SIS SIS-REWE Go before 7.7 SP17 allows XSS: rewe/prod/web/index.php (affected parameters are config, version, win, db, pwd, and user) and /rewe/prod/web/rewe_go_check.php (version and all other parameters).

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMSIS Informatik REWE GO SP17 <7.7 - Cross-Site ScriptingCVSS 6.1

SIS Informatik REWE GO SP17 before 7.7 contains a cross-site scripting vulnerability via rewe/prod/web/index.php (affected parameters are config, version, win, db, pwd, and user) and /rewe/prod/web/rewe_go_check.php (version and all other parameters).

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

To remediate this issue, ensure that all user-supplied input is properly validated and sanitized before being displayed on web pages.

WeaknessesCWE-79
Authorsgeeknik
Template tagscve2021cvexssseclistsintrusivesisinformatikvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:sisinformatik:sis-rewe_go:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4