
Description: Keycloak 8.0 and prior contains a cross-site scripting vulnerability. An attacker can execute arbitrary script and thus steal cookie-based authentication credentials and launch other attacks. A lack of proper input validation made it possible for an attacker to execute malicious JavaScript code on ████████ This reflected XSS would execute after making a POST request with an XSS payload in the path of the request. As a result, the server would directly insert the payload into the response, allowing the XSS to trigger on the page. References https://cure53.de/pentest-report_keycloak.pdf https://hackerone.com/reports/87040 Impact If successful, a cross site scripting attack can severely impact websites and web applications, damage their reputation and relationships with customers. XXS can deface websites, can result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user's device. System Host(s) ███ Affected Product(s) and Version(s) █████ CVE Numbers Steps to Reproduce Navigate visit URL https://████/ Second step as long as I use recconaisetool I can find hidden directory path 403 / 200 Found directory on "/auth/realms/master/clients-registrations/openid-connect" I see this server used keycloack. and lets see the versions used chrome-extentions The server is vulnerable to (XSS) Keycloack 8.0 Intercept request to burp-suite and change GET Request to POST Request Here's the HTTP Parameter request that the...
SOCIAL SHARE CARD GENERATOR