-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 secunet Security Networks AG Security Advisory Advisory: SECURE DATA SPACE API Multiple Non-Persistent Cross-Site Scripting Vulnerabilities 1. DETAILS - ---------- Product: SECURE DATA SPACE Vendor URL: www.ssp-europe.eu Type: Cross-site Scripting[CWE-79] Date found: 2015-09-30 Date published: 2015-12-09 CVSSv2 Score: 4,3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CVE: CVE-2015-7706 2. AFFECTED VERSIONS - -------------------- All product versions (Online, Dedicated, For Linux/Windows) in Web-Client v3.1.1-2 restApiVersion: 3.5.7-FINAL sdsServerVersion: 3.4.14-FINAL 3. INTRODUCTION - --------------- "The highly secure business solution for easy storage, synchronization, distribution and management of data - regardless of location or device" (from the vendor's homepage) 4. VULNERABILITY DETAILS - ------------------------ The Secure Data Share version v3.1.1-2 is vulnerable to multiple unauthenticated Non-Persistent Cross-Site Scripting vulnerabilities when user-supplied input is processed by the server.[0] #1 Proof-of-Concept: https://example.com/api/v3//public/shares/downloads/111"}
#2 Proof-of-Concept(authType parameter): POST /api/v3/auth/login {"login":"a","password":"a","language":1,"authType":"random