lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Mon, 13 Jul 2020 19:32:35 +0000 From: Ryan Delaney <ryan.delaney@...sp.org> To: fulldisclosure@...lists.org Subject: [FD] Verint Impact 360 Open iFrame <!-- # Exploit Title: Verint Impact 360 Open iFrame # Date: 7-13-2020 # Exploit Author: Ryan Delaney # Author Contact: ryan.delaney@...sp.org # Author LinkedIn: https://www.linkedin.com/in/infosecrd/ # Vendor Homepage: https://www.verint.com/ # Software Link: https://www.verint.com/engagement/our-offerings/solutions/workforce-optimization/ # Version: Impact 360 v15.1 # Tested on: Impact 360 v15.1 # CVE: CVE-2019-12773 1. Description An issue was discovered in Verint Impact 360 15.1. At wfo/help/help_popup.jsp, the helpURL parameter can be changed to embed arbitrary content inside of an iFrame. Attackers may use this in conjunction with social engineering to embed malicious scripts or phishing pages on a site where this product is installed, given the attacker can convince a victim to visit a crafted link. 2. Mitigation Restrict Impact 360 accessibility to internal network only. Verint has not patched this vulnerability to my knowledge, despite having been made aware of it over a year ago. 3. PoC Withheld due to possible legal threat. 4. Timeline Discovered: 6-7-2019 CVE assigned: 6-10-2019 First contact: 6-14-2019 (no response) Follow-up 1: 6-25-2019 Reply received: 7-9-2019 (stating that the responsible disclosure line was for the community edition and report would be forwarded to enterprise) Follow-up 2: 7-16-2019 Reply received: 7-19-2019 (cc'ing another individual and asking them to follow up with me) Follow-up 3: 8-30-2019 (no response) Follow-up 4: 9-4-2019 (no response) Follow-up 5: 9-11-2019 (no response) Follow-up 6: 1-6-2020 (notification of intent to disclose in 90 days, no response) Follow-up 7: 3-5-2020 (notification of intent to disclose in 30 days) Reply received: 3-6-2020 (requesting addition delay for disclosure) Follow-up 8: 3-27-2020 (no response) Follow-up 9: 5-18-2020 (no response) Follow-up 10: 6-25-2020 (notification of intent to disclose, requesting confirmation that legal action will not be pursued, no response) Published: 7-13-2020 (260 business days after initial report) --> _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Powered by blists - more mailing lists