Record summary

CVE-2023-41642 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Multiple reflected cross-site scripting (XSS) vulnerabilities in the ErroreNonGestito.aspx component of GruppoSCAI RealGimm 1.1.37p38 allow attackers to execute arbitrary Javascript in the context of a victim user's browser via a crafted payload injected into the VIEWSTATE parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 24, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 1, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMRealGimm by GruppoSCAI v1.1.37p38 - Cross-Site ScriptingCVSS 6.1

Multiple reflected cross-site scripting (XSS) vulnerabilities in the ErroreNonGestito.aspx component of GruppoSCAI RealGimm 1.1.37p38 allow attackers to execute arbitrary Javascript in the context of a victim user's browser via a crafted payload injected into the VIEWSTATE parameter.

Impact

Unauthenticated attackers can inject malicious JavaScript via the VIEWSTATE parameter in ErroreNonGestito.aspx to steal session cookies and perform actions as victim users of the RealGimm property management system.

Remediation

Update GruppoSCAI RealGimm to a version newer than 1.1.37p38 that properly sanitizes the VIEWSTATE parameter in the ErroreNonGestito.aspx component.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2023realgimmxssgrupposcaivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:grupposcai:realgimm:1.1.37:p38:*:*:*:*:*:*

Source: ProjectDiscovery

References

3