Ericsson ECM (Enterprise Content Management) solution Vulnerable to Stored XSS. ( CVE-2021-41391)

 Dear Reader,

I was able to identify stored XSS in Ericsson ECM (Enterprise Content Management) solution Version: 18.0 (0331) R1E 

CVE ID: CVE-2021-41391

Below are its details:


# Software description:
Ericsson Catalog Manager allows customers to rapidly launch and enable new innovative offerings with simple user experience and enterprise product, service & resource catalog capabilities. 

# Technical Details & Impact:

It was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored XSS, In most test cases session hijacking was also possible by utilizing the XSS vulnerability. This potentially allows for full account takeover, or exploiting admin's browsers using beef framework.

# POC
  1. Login as normal user in ECM 
  2. Click on User Profile Management and click on Preference Definition or just visit this URL "https://host:port/ecm/securityManagement " change the host/port to your ECM host/port
  3. Edit or create new Preference Definition
  4.  In Name field write anything, in label field write your malicious script. For test case we used only alert('XSS') as show below
  5. Click on Save button 
Your script is stored and will be executed on All users of ECM platform as shown below. 



Vulnerability has been reported to Ericsson and is fixed in latest version after 18.0.

Thanks

Comments

Popular posts from this blog

GRANDING UTime Master - IDOR (CVE-2023-45393)

GRANDING UTime Master - Stored XSS (CVE-2023-45391)

Ericsson BSCS iX R18 Billing & Rating (ADMX, MX) - Stored XSS (CVE-2020-29144, CVE-2020-29145)