Skip to content

Latest commit

 

History

History
24 lines (20 loc) · 1.16 KB

CVE-2023-50639.md

File metadata and controls

24 lines (20 loc) · 1.16 KB

Exploit Title: [There is a PDF XSS vulnerability in file upload function of CuteHttpFileServer]

Google Dork: [CuteHttpFileServer]

Date: [December 5th, 2023]

Exploit Author: [zhongdongxu]

Vendor Homepage: [http://iscute.cn/chfs]

Version: [CuteHttpFileServer/v1.0 - CuteHttpFileServer/v2.0]

Tested on: [windows/remote]

CVE : [CVE-2023-50639]

detail:

for example,

File upload function is here.

kappframework-FhxYJC(1)

I uploaded a PDF with malicious code.

kappframework-FVvNxQ(1)

When the user opens it in Google Chrome,the code will be triggered.

kappframework-dZwKoq(1)

PDF file for uploading.

result1.pdf

The URL with vulnerabilities were replied to in the email,thank you!