CVE-2023-41642
grupposcai realgimm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2023-41642 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Multiple reflected cross-site scripting (XSS) vulnerabilities in the ErroreNonGestito.aspx component of GruppoSCAI RealGimm 1.1.37p38 allow attackers to execute arbitrary Javascript in the context of a victim user's browser via a crafted payload injected into the VIEWSTATE parameter.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 24, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 1, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
realgimmBrowse grupposcai / realgimm | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMRealGimm by GruppoSCAI v1.1.37p38 - Cross-Site ScriptingCVSS 6.1
Multiple reflected cross-site scripting (XSS) vulnerabilities in the ErroreNonGestito.aspx component of GruppoSCAI RealGimm 1.1.37p38 allow attackers to execute arbitrary Javascript in the context of a victim user's browser via a crafted payload injected into the VIEWSTATE parameter.
Impact
Unauthenticated attackers can inject malicious JavaScript via the VIEWSTATE parameter in ErroreNonGestito.aspx to steal session cookies and perform actions as victim users of the RealGimm property management system.
Remediation
Update GruppoSCAI RealGimm to a version newer than 1.1.37p38 that properly sanitizes the VIEWSTATE parameter in the ErroreNonGestito.aspx component.
Source: ProjectDiscovery