Sploitus

Exploit for CVE-2023-49977

kitploit Β· 2026-08-25

Exploit Code

MARKDOWN31 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-GERALDOALCANTARA-CVE-2023-49977
# CVE-2023-49977

# 고객 지원 μ‹œμŠ€ν…œ 1.0 - "customer_list" νŽ˜μ΄μ§€μ˜ "Address" ν•„λ“œ/λ§€κ°œλ³€μˆ˜μ—μ„œμ˜ ꡐ차 μ‚¬μ΄νŠΈ μŠ€ν¬λ¦½νŒ…(XSS) 취약점

**μ„€λͺ…** : 고객 지원 μ‹œμŠ€ν…œ 1.0은 μ €μž₯ν˜• XSS에 μ·¨μ•½ν•©λ‹ˆλ‹€. 고객 지원 μ‹œμŠ€ν…œ 버전 1에 XSS 취약점이 μ‘΄μž¬ν•©λ‹ˆλ‹€. μ•…μ˜μ μΈ ν–‰μœ„μžκ°€ 고객을 νŽΈμ§‘/생성할 λ•Œ "Address" ν•„λ“œ/λ§€κ°œλ³€μˆ˜λ₯Ό 톡해 JavaScript μ½”λ“œλ₯Ό μ‚½μž…ν•  수 μžˆμŠ΅λ‹ˆλ‹€. 이 μ½”λ“œλŠ” "/customer_support/index.php?page=customer_list" νŽ˜μ΄μ§€μ— λ°©λ¬Έν•  λ•Œλ§ˆλ‹€ μ‹€ν–‰λ©λ‹ˆλ‹€.

**μ·¨μ•½ν•œ μ œν’ˆ 버전** : 고객 지원 μ‹œμŠ€ν…œ 1.0  
**CVE μž‘μ„±μž** : Geraldo AlcΓ’ntara  
**λ‚ μ§œ** : 2023λ…„ 11μ›” 28일  
**확인일** : 2023λ…„ 12μ›” 19일  
**CVE** : CVE-2023-49977  
**ν…ŒμŠ€νŠΈ ν™˜κ²½** : Windows

### μž¬ν˜„ 단계:

  1. μ• ν”Œλ¦¬μΌ€μ΄μ…˜μ— λ‘œκ·ΈμΈν•©λ‹ˆλ‹€.
  2. κΈ°μ‘΄ 고객을 νŽΈμ§‘ν•˜λ €λ©΄ "/customer_support/index.php?page=customer_list"둜 μ΄λ™ν•˜κ±°λ‚˜, μƒˆ 고객을 μƒμ„±ν•˜λ €λ©΄ "/customer_support/index.php?page=new_customer"둜 μ΄λ™ν•©λ‹ˆλ‹€.
  3. 고객을 μƒμ„±ν•˜κ±°λ‚˜ νŽΈμ§‘ν•˜κ³  μ•…μ„± νŽ˜μ΄λ‘œλ“œλ₯Ό "Address" ν•„λ“œ/λ§€κ°œλ³€μˆ˜μ— μ‚½μž…ν•©λ‹ˆλ‹€.
  4. νŽ˜μ΄λ‘œλ“œ:



root@kitploit:~
    
    
    </dt></b><script>alert(document.domain)</script>
    

발견자(λ“€)/ν¬λ ˆλ”§:  
Geraldo AlcΓ’ntara