vendor:
Xeams
by:
Marlow Tannhauser
7.5
CVSS
HIGH
CSRF/Stored XSS
352
CWE
Product Name: Xeams
Affected Version From: 4.5 Build 5755
Affected Version To: 4.5 Build 5755
Patch Exists: YES
Related CWE: 2015-3141 (Xeams)
CPE: a:synametrics:xeams:4.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Web apps
2015
Multiple vulnerabilities in Xeams 4.5 Build 5755 (CSRF/Stored XSS)
Xeams 4.5 Build 5755 is vulnerable to CSRF attacks, which can also be combined with stored XSS attacks (authenticated administrators only). The JSESSIONID created when a user logs on to the system is persistent and does not change across requests. The following PoC uses the CSRF vulnerability to create a new SMTP domain in the application, and combines it with one of the stored XSS vulnerabilities. The following PoC uses the CSRF vulnerability to create a new user with the details shown.
Mitigation:
Ensure that the application is updated to the latest version of Xeams, and that all users are authenticated before performing any sensitive operations.