Record summary

CVE-2023-36306 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php components.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 10, 2024 · Source: CVE List

Proofs of concept

1

Catalogued exploits

ExploitDBAdiscon LogAnalyzer v.4.1.13 - Cross Site ScriptingExploitDB exploitby PedroNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMAdiscon LogAnalyzer v.4.1.13 - Cross-Site ScriptingCVSS 6.1

A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php

Impact

Unauthenticated attackers can inject malicious JavaScript through the uid parameter in asktheoracle.php, potentially stealing administrator session cookies and accessing sensitive log analysis data.

Remediation

Update Adiscon LogAnalyzer to a version newer than 4.1.13 that properly sanitizes the uid parameter and encodes output in asktheoracle.php.

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscve2023cvexssunauthexploitdbadisconadiscon-loganalyzervuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:adiscon:loganalyzer:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2