TenderDocTransfer 0.41.151-0.41.157 - Unauthenticated Reflected Cross-Site Scripting via API
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-12641. PoCs published by Jimmy01240397.
AI-analyzed exploit summary The repository lacks functional exploit code and instead provides YouTube demo links and a basic Docker setup, which is insufficient for technical validation. No technical details or PoC code are included, raising suspicion.
Description
TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use specific APIs through phishing to execute arbitrary JavaScript code in the user’s browser. Since the web server set by the application supports Node.Js features, attackers can further leverage this to run OS commands.
Exploits (1)
The repository lacks functional exploit code and instead provides YouTube demo links and a basic Docker setup, which is insufficient for technical validation. No technical details or PoC code are included, raising suspicion.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H