Charles River Admin Panel Reflected Cross Site Scripting

About Charles River:

Charles River provides an executable for high profile people which helps them to make decision about investment. It has some automated algorithm which performs the calculation and analysis and help the user to take investment decision.
This executable has an admin panel which is accessible through web browser.

Vulnerability:
The admin website of Charles River is vulnerable to post authentication cross site scripting vulnerability.
The file configPopup.do has parameter "n" which is vulnerable to reflected cross site scripting.

Exploit URL:

domain.com:8081/crts/admin/failover/configPopup.do?n=beanEventPublisher%3cscript%3ealert(1)%3c%2fscript%3e



Solution:
Not yet rolled out

Disclosure Timeline:
August 2018: Informed to Charles River - No reply
December 2018:Reminder mail sent through Contact Us - No reply
January 1 2019: Full disclosure.




Comments

  1. Hello Everone

    Fullz available in bulk quantity
    Fresh spammed & verified info

    SSN DOB DL ADDRESS
    SIN DOB ADDRESS MMN
    NIN DOB ADDRESS SORT CODE

    USA UK CANADA All states info fullz available
    Good Credit Scores & High quality info
    All info will be valid & Genuine spammed not generated

    Contact me here

    What's App = +1... 727... 788.. 6129..
    Tele Gram = @ killhacks - @ leadsupplier
    Email = bigbull0334 at g mail dot com
    Skype = @ peeterhacks

    USA All info available with guarantee
    DL Photos Front Back with SSN
    High Credit Scores Pros
    DL Fullz with issue & exp dates
    UK & Canada DL Front back with selfie
    Passport Photos
    SSN DOB DL Fullz
    SIN DOB ADDRESS MMN Fullz
    NIN DOB DL ADDRESS SORT CODE ACCOUNT NUMBER Fullz
    Young & Old Age Fullz
    CC with CVV
    Dumps with Pin codes

    All stuff will be fresh & valid
    Feel free to contact me

    #fullz #ssnfullz #ssndlfullz #usafullz #ccfullzcvv
    #ukfullz #ukdobaddress #ninukdl #ninDL #uknindobdl #ninsortcode
    #sinfullz #canadafullz #sinnindob #prosCC #ccdumps #sellfullzpros

    ReplyDelete

Post a Comment

Popular posts from this blog

MY OSCP REVIEW

Minishare 1.4.1 Bufferoverflow