Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

CVE-2024-54795 PoC — Engineering SpagoBI 跨站脚本漏洞

Source
Associated Vulnerability
Title:Engineering SpagoBI 跨站脚本漏洞 (CVE-2024-54795)
Description:SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function.
Description
SpagoBI multiple stored xss
Readme
# CVE-2024-54795

**Severity :** **Medium** (**5.4**)

**CVSS score :** `CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N` 

## Summary :
Engineering Ingegneria Informatica **SpagoBI** version **3.5.1** is affected by multiple **stored XSS** inside of the worksheet designer page.

## Poc

### Steps to Reproduce :
1. While editing a document inserting custom text or while seving inserting filename and info insert the following payload:
  ```
    "><img src="#" onerror=alert(1)>
  ```
2. Visit the home/worksheet designer page and the pages of the file saved. The html will be reflected and the alert prompted.

## Affected Version Details :

- <= 3.5.1

## Impact :

If the attacker is logged into the app with sufficient permissions to access the worksheet designer page, can store a JS script that can steal user cookies, perform horizontal/vertical privilege escalation, or perform malicious actions such as downloading a malicious file.

## Mitigation :

-  Update to the latest version.
  
## References :
- 
File Snapshot

[4.0K] /data/pocs/391533b31df38d52396241f937d39ccfef963079 └── [1014] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →