diff --git a/2023/CVE-2023-33145/docs/Screenshot 2023-07-06 123726.png b/2023/CVE-2023-33145/docs/Screenshot 2023-07-06 123726.png new file mode 100644 index 0000000..3850dcc Binary files /dev/null and b/2023/CVE-2023-33145/docs/Screenshot 2023-07-06 123726.png differ diff --git a/2023/CVE-2023-33145/docs/report.txt b/2023/CVE-2023-33145/docs/report.txt new file mode 100644 index 0000000..a35b10f --- /dev/null +++ b/2023/CVE-2023-33145/docs/report.txt @@ -0,0 +1,54 @@ +## Title: Microsoft Edge - 114.0.1823.67 (Official build) (64-bit)-(Chromium-based) Information Disclosure. +## Author: nu11secur1ty +## Date: 07.06.2023 +## Vendor: https://www.microsoft.com/ +## Software: https://www.microsoft.com/en-us/edge?form=MA13FJ&exp=e415 +## Reference: https://portswigger.net/web-security/information-disclosure, https://www.softwaresecured.com/stride-threat-modeling/ +## CVE-2023-33145 + + + +## Description: +The type of information that could be disclosed if an attacker successfully exploited this vulnerability is data inside the targeted website like IDs, tokens, nonces, cookies, IP, User-Agent, and other sensitive information. +The user would have to click on a specially crafted URL to be compromised by the attacker. +In this example, the attacker use STRIDE Threat Modeling to spoof the victim to click on his website and done. +This will be hard to detect. + +## Conclusion: +Please be careful, for suspicious sites or be careful who sending you an link to open! + +## Staus: HIGH Vulnerability + +[+]Exploit: + +- Exploit Server: + +```js +## This is a Get request from the server when the victims click! And it is enough to understand this vulnerability! =) + + + +## WARNING: The PoCsess.php will be not uploaded for security reasons! +## BR nu11secur1ty + +``` + +## Reproduce: +[href](https://github.com/nu11secur1ty/Windows11Exploits/tree/main/2023/CVE-2023-33146) + +## Proof and Exploit +[href](https://www.nu11secur1ty.com/2023/07/cve-2023-33145-microsoft-edge.html) + +## Time spend: +01:30:00 + + +-- +System Administrator - Infrastructure Engineer +Penetration Testing Engineer +Exploit developer at https://packetstormsecurity.com/ https://cve.mitre.org/index.html +https://cxsecurity.com/ and https://www.exploit-db.com/ +0day Exploit DataBase https://0day.today/ +home page: https://www.nu11secur1ty.com/ +hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E= + nu11secur1ty