Vendor description
"SIS Informatik is your specialist for the conception and implementation of tailor-made accounting, business intelligence and corporate performance management solutions. In addition to technical competence, business know-how and the willingness to develop optimal, adaptable software solutions together with our customers are the central components that make us a strong partner. We develop solutions based on high-quality technologies from well-known partners such as IBM, Oracle and Qlik" (translated from German)
Source: https://sisinformatik.com/unternehmen/
Business recommendation
The vendor provides a patch which should be installed immediately. SEC Consult recommends to perform a thorough security review of these products conducted by security professionals to identify and resolve all security issues.
Vulnerability overview/description
1) Multiple Reflected Cross-Site Scripting (XSS) (CVE-2021-31537)
The login website returns unfiltered or unescaped user input. This leads to a reflected cross-site scripting (XSS) vulnerability. An attacker can inject arbitrary HTML or JavaScript code into the victim's web browser. Once the victim clicks on a malicious link, the attacker's code is executed in the context of the victim's web browser.
Proof of concept
1) Multiple Reflected Cross-Scripting (XSS) (CVE-2021-31537)
When opening the following URL the supplied JavaScript code will be executed.
/rewe/prod/web/index.php?config=rewe2%22%3E%3Cscript%3Ealert(%22document.domain%22)%3C/script%3E&version=7.5.0&win=2707&user=test&pwd=test&db=test&continue=false
The affected parameters are: "config", "version", "win","db", "pwd", and "user".
No valid parameters need to be supplied to trigger the XSS vulnerability as seen in following URL:
/rewe/prod/web/index.php?abc'-alert(%22document.domain%22)-'abc=1
The following URL is affected as well:
/rewe/prod/web/rewe_go_check.php?config=rewe&version=7.5.0%3cscript%3ealert(1)%3c%2fscript%3e&win=2707
All parameters are affected.
Vulnerable / tested versions
The following product/firmware version has been tested:
- SIS-REWE GO 7.5.0/12C