Charles River Admin Panel Reflected Cross Site Scripting
About Charles River:
Charles River provides an executable for high profile people which helps them to make decision about investment. It has some automated algorithm which performs the calculation and analysis and help the user to take investment decision.
This executable has an admin panel which is accessible through web browser.
Vulnerability:
The admin website of Charles River is vulnerable to post authentication cross site scripting vulnerability.
The file configPopup.do has parameter "n" which is vulnerable to reflected cross site scripting.
Exploit URL:
domain.com:8081/crts/admin/failover/configPopup.do?n=beanEventPublisher%3cscript%3ealert(1)%3c%2fscript%3e
Solution:
Not yet rolled out
Disclosure Timeline:
August 2018: Informed to Charles River - No reply
December 2018:Reminder mail sent through Contact Us - No reply
January 1 2019: Full disclosure.
Charles River provides an executable for high profile people which helps them to make decision about investment. It has some automated algorithm which performs the calculation and analysis and help the user to take investment decision.
This executable has an admin panel which is accessible through web browser.
Vulnerability:
The admin website of Charles River is vulnerable to post authentication cross site scripting vulnerability.
The file configPopup.do has parameter "n" which is vulnerable to reflected cross site scripting.
Exploit URL:
domain.com:8081/crts/admin/failover/configPopup.do?n=beanEventPublisher%3cscript%3ealert(1)%3c%2fscript%3e
Solution:
Not yet rolled out
Disclosure Timeline:
August 2018: Informed to Charles River - No reply
December 2018:Reminder mail sent through Contact Us - No reply
January 1 2019: Full disclosure.
Hello Everone
ReplyDeleteFullz available in bulk quantity
Fresh spammed & verified info
SSN DOB DL ADDRESS
SIN DOB ADDRESS MMN
NIN DOB ADDRESS SORT CODE
USA UK CANADA All states info fullz available
Good Credit Scores & High quality info
All info will be valid & Genuine spammed not generated
Contact me here
What's App = +1... 727... 788.. 6129..
Tele Gram = @ killhacks - @ leadsupplier
Email = bigbull0334 at g mail dot com
Skype = @ peeterhacks
USA All info available with guarantee
DL Photos Front Back with SSN
High Credit Scores Pros
DL Fullz with issue & exp dates
UK & Canada DL Front back with selfie
Passport Photos
SSN DOB DL Fullz
SIN DOB ADDRESS MMN Fullz
NIN DOB DL ADDRESS SORT CODE ACCOUNT NUMBER Fullz
Young & Old Age Fullz
CC with CVV
Dumps with Pin codes
All stuff will be fresh & valid
Feel free to contact me
#fullz #ssnfullz #ssndlfullz #usafullz #ccfullzcvv
#ukfullz #ukdobaddress #ninukdl #ninDL #uknindobdl #ninsortcode
#sinfullz #canadafullz #sinnindob #prosCC #ccdumps #sellfullzpros