vendor:
FIBARO System
by:
LiquidWorm
7.5
CVSS
HIGH
Remote File Include
94
CWE
Product Name: FIBARO System
Affected Version From: Home Center 3, Home Center 2, Home Center Lite 5.021.38
Affected Version To: 4.180
Patch Exists: NO
Related CWE: N/A
CPE: a:fibar_group_s.a.:fibaro_system:5.021.38
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Apache/2.2.16 (Debian), nginx/1.9.5, nginx/1.8.0, lighttpd/1.4.41
2020
FIBARO System Home Center 5.021 – Remote File Include
The smart home solution is vulnerable to a remote Cross-Site Scripting triggered via a Remote File Inclusion issue by including arbitrary client-side dynamic scripts (JavaScript, VBScript) due to the undocumented proxy API and its url GET parameter. This allows hijacking the current session of the user or changing the look of the page by changing the HTML.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in a web request.