Title: ====== GroupWare epesiBIM CRM 1.2.1 - Multiple Web Vulnerabilities Date: ===== 2012-04-10 References: =========== http://www.vulnerability-lab.com/get_content.php?id=501 VL-ID: ===== 501 Introduction: ============= epesi BIM stands for Business Information Manager. We just did not like the name CRM (Customer Relationship Management), because with epesi you can manage not only customer\\\\\\\\\\\\\\\'s data, but also internal business records like employees, inventory, etc. epesi BIM has modular design. Some modules provide basic, low-level functions like user authentication (login), managing sessions, database connectivity, data entry verification etc. Think of modules as building blocks - you can stack them - one on top of another - to create different shapes. The same way with epesi framework and included modules you can create web application with different functionality: CRM, SFA, ERP or SCM. In fact we created already: - CRM package (inlcuded in the FREE version) - Warehouse Management System - Custom Sales and Commision Reporting tool - Complete inventory management system integrated with e-commerce - School Register with student and courses management - and many more custom solutions (Copy of the Vendor Homepage: http://www.epesibim.com ) Abstract: ========= The Vulnerability Laboratory Researcher Team discovered multiple Web Vulnerabilities on GroupWare`s epesiBIM CRM v1.2.1. Report-Timeline: ================ 2012-04-10: Public or Non-Public Disclosure Status: ======== Published Exploitation-Technique: ======================= Remote Severity: ========= Medium Details: ======== Multiple persistent input validation vulnerabilities are detected on GroupWares epesiBIM 1.2.1 web application. The bugs allow remote attackers to implement/inject malicious script code on the application side (persistent). Successful exploitation of the vulnerability can lead to session hijacking (manager/admin) or stable (persistent) context manipulation. Exploitation requires low user inter action. The bug is located on the Description input field of the application which allows to execute code out of the main application dashboard context. Vulnerable Module(s): [+] Meeting Description Input Fields [-] Agenda Display Dashboard - Title of Description [-] Calender Content Display - Title of Description Picture(s): ../1.png ../2.png ../3.png ../4.png Proof of Concept: ================= The vulnerability can be exploited by remote attacker or local low privileged user accounts with low required user inter action. For demonstration or reproduce ... Review: Agenda Display Dashboard - Title from Description ​​​​​Today, 06:20 ​​​​​DateMon - 09 Apr 2012Time< TD bgcolor="white" style="word-wrap: break-word;">06:20 - 07:20Duration1 hour(s) Event" >& lt;iframe src=a onload=alert("Vunerabilitylab") <Description& lt;/STRONG>" >