CVE-2023-54341
MEDIUMWebgrind < 1.1 - Unauthenticated Reflected Cross-Site Scripting via File Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-54341. PoCs published by Rafael Pedrero.
AI-analyzed exploit summary The exploit demonstrates a Remote Command Execution (RCE) and Reflected Cross-Site Scripting (XSS) vulnerability in Webgrind 1.1. The RCE is achieved by injecting OS commands via the 'dataFile' parameter, while the XSS is triggered through the 'file' parameter in the 'fileviewer' operation.
Description
Webgrind 1.1 and before contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts via the file parameter in index.php. The application does not sufficiently encode user-controlled inputs, allowing attackers to execute arbitrary JavaScript in victim's browsers by crafting malicious URLs.
Exploits (1)
The exploit demonstrates a Remote Command Execution (RCE) and Reflected Cross-Site Scripting (XSS) vulnerability in Webgrind 1.1. The RCE is achieved by injecting OS commands via the 'dataFile' parameter, while the XSS is triggered through the 'file' parameter in the 'fileviewer' operation.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N