漏洞描述 IBM Aspera Console是美国国际商业机器(IBM)公司的一个基于 Web 的应用程序。允许用户集中管理、监控和控制 Aspera 服务器(节点)和传输。 IBM Aspera Console 3.4.4及之前版本存在跨站脚本漏洞,该漏洞源于允许嵌入任意JavaScript代码,可能导致凭据泄露。
相关漏洞推荐 POC keycloak-admin-console-config: Keycloak Admin Console Configuration Disclosure POC rails-history-exposure: Rails/Ruby Console History - Exposure POC jboss-jmx-console-unauth: JBoss JMX Console - Unauthenticated Access POC cockroachdb-unauth-exposure: CockroachDB Unauthenticated Console Exposure Apache ActiveMQ Artemis Console存在默认账号密码 POC CVE-2015-3224: Ruby on Rails Web Console - Remote Code Execution POC CVE-2018-17431: Comodo Unified Threat Management Web Console - Remote Code Execution POC CVE-2018-19439: Oracle Secure Global Desktop Administration Console 4.4 - Cross-Site Scripting POC CVE-2019-2729: Oracle WebLogic Server Administration Console - Remote Code Execution POC CVE-2020-14883: Oracle Fusion Middleware WebLogic Server Administration Console - Remote Code Execution POC CVE-2020-17453: WSO2 Carbon Management Console <=5.10 - Cross-Site Scripting POC CVE-2021-41266: MinIO Operator Console Authentication Bypass POC CVE-2022-24856: Flyte Console <0.52.0 - Server-Side Request Forgery