Kaaproject Kaa IoT Platform 跨站脚本漏洞

漏洞ID 2235986 漏洞类型 跨站脚本
发布时间 2020-11-16 更新时间 2020-11-17
CVE编号 CVE-2020-26701

CNNVD-ID CNNVD-202011-1442
漏洞平台 N/A CVSS评分 N/A
Kaaproject Kaa IoT Platform是Kaaproject组织的一个企业级物联网平台。该平台为多种设备提供协议支持,为已连接的设备提供监控、数据管理等功能。
Kaa IoT Platform v1.2.0版本存在跨站脚本漏洞,该漏洞允许远程攻击者通过描述参数注入恶意web脚本或HTML注入有效载荷。
漏洞EXP
#Exploit Title: Kaa IoT Platform 1.2.0 Cross Site Scripting (XSS)
Vulnerability8 | | t @ J T *
#Date: 2020-10-01
#Exploit Author: Mufaddal Masalawala
#Vendor Homepage: https://www.kaaproject.org/
#Software Link: https://cloud.kaaiot.com/
#Version: 1.2.0
#Tested on: Kali Linux 2020.3
#CVE: CVE-2020-26701
#Proof Of Concept:
Cross-site scripting (XSS) vulnerability in Dashboards section in Kaa IoT
Platform v1.2.0 allows remote attackers to inject malicious web scripts or
HTML Injection payloads via the Description parameter.
To exploit this vulnerability:
1. Open Firefox browser, login to the cloud.kaaiot.com and access the
dashboard
2. Go to 'Solutions' module, select any one solution(create if not
present) and click on it.
3. Now in the Dashboards module, edit the Dashboard.
4. in Description, enter the payload <img src="https://www.anquanke.com/vul/id/2235986/x"
onerror="alert(window.location)" /> and click 'Update'.
5. Open that Dashboard and you'll receive an alert executing user
supplied script in the browser.

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/160082/Kaa-IoT-Platform-1.2.0-Cross-Site-Scripting.html