
Reflektiertes Cross-Site Scripting in TOTVS Fluig Plataform 1.6.X - 1.8.1
Die TOTVS Fluig-Plattform ist in ihren Versionen von 1.6.1.X bis 1.8.1 anfällig für Cross-Site-Scripting in den Parametern 'redirectUrl' und 'user' innerhalb des Moduls 'mobileredir'.
Fluig ist die Produktivitäts- und Kollaborationsplattform, die in das ERP-System integriert ist. Sie wurde vom größten Technologieunternehmen Brasiliens, TOTVS, entwickelt und auf dem Server des Kunden gehostet.
Betroffene Versionen:
-- Fluig 1.6.X - Fluig 1.8.1 …
https://fluig.host.com/mobileredir/openApp.jsp?redirectUrl=PAYLOAD
https://fluig.host.com/mobileredir/openApp.jsp?user=PAYLOAD
https://fluig.host.com/mobileredir/openApp.jsp?redirectUrl="> https://fluig.host.com/mobileredir/openApp.jsp?user=">