CVE-2024-12641

CRITICAL LAB

TenderDocTransfer 0.41.151-0.41.157 - Unauthenticated Reflected Cross-Site Scripting via API

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-12641. PoCs published by Jimmy01240397.

AI-analyzed exploit summary The repository lacks functional exploit code and instead provides YouTube demo links and a basic Docker setup, which is insufficient for technical validation. No technical details or PoC code are included, raising suspicion.

Description

TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use specific APIs through phishing to execute arbitrary JavaScript code in the user’s browser. Since the web server set by the application supports Node.Js features, attackers can further leverage this to run OS commands.

Exploits (1)

nomisec SUSPICIOUS 1 stars
by Jimmy01240397 · poc
https://github.com/Jimmy01240397/CVE-2024-12641_12642_12645

The repository lacks functional exploit code and instead provides YouTube demo links and a basic Docker setup, which is insufficient for technical validation. No technical details or PoC code are included, raising suspicion.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: Unknown
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/tw/cp-132-8292-4fd98-1.html
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/en/cp-139-8299-42168-2.html

Scores

CVSS v3 9.6
EPSS 0.0134
EPSS Percentile 67.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Lab Environment

COMMUNITY
Community Lab
docker pull nginx:1-alpine

Details

CWE
CWE-79
Status published
Products (1)
cht/tenderdoctransfer 0.41.151 - 0.41.157
Published Dec 16, 2024
Tracked Since Feb 18, 2026