Ethical Hacking Automation

Automate Recon and scanning process with Vidoc. All security teams in one place

KafDrop - Cross-Site Scripting

By kannthu

High
Vidoc logoVidoc Module
#kafdrop#xss
Description
Author: dhiyaneshDk Classification CWE-ID: CWE-79 CVSS-Metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N CVSS-Score: 7.2 KafDrop contains a cross-site scripting vulnerability. It allows remote unauthenticated attackers to inject arbitrary HTML and/or JavaScript into the response returned by the server. Reference - https://github.com/HomeAdvisor/Kafdrop/issues/12 - https://www.blackhatethicalhacking.com/news/apache-kafka-cloud-clusters-expose-sensitive-data-for-large-companies Metadata max-request: 1

Module preview

Concurrent Requests (1)
1. HTTP Request template
GET/topic/e'%22%3E%3Cim...
Matching conditions
word: Kafdrop, <img src=x onerror=alert(2)>and
status: 500
Passive global matcher
No matching conditions.
On match action
Report vulnerability