-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Advisory ID: SYSS-2017-003 Product: Simplessus Files Manufacturer: Simplessus Affected Version(s): 3.7.7 Tested Version(s): 3.7.7 Vulnerability Type: Open Redirect (CWE-601) Risk Level: Medium Solution Status: Fixed Manufacturer Notification: January 25, 2017 Solution Date: January 25, 2017 Public Disclosure: February 16, 2017 CVE Reference: Not yet assigned Author of Advisory: Dr. Adrian Vollmer, SySS GmbH ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Product overview: Simplessus Files is a file sharing web application. The manufacturer describes the product as follows (see [1]): Simplessus Files is a simple software solution to exchange files and documents over the internet. No more file sharing via e-mail, FTP or CD-ROM with Simplessus Files replace very large files online easily. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Vulnerability overview: Due to insufficient filtering of user controlled input, Simplessus Files is vulnerable to an open redirect weakness. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Vulnerability Details: Any value of the GET parameter 'core[redirect]' is accepted as the target of a redirection. This can make phishing attacks much more credible. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Proof of Concept (PoC): The following link immediately leads to a redirection to the website at https://www.syss.de. https:///?core[redirect]=https%3A%2F%2Fwww.syss.de ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Solution: Update to software version to 3.8.3. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Disclosure Timeline: 2017-01-13: Vulnerability discovered 2017-01-25: Vulnerability reported 2017-01-25: Vendor confirmation 2017-02-15: Public disclosure ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ References: [1] Product website for Simplessus Files http://files.simplessus.com [2] SySS Security Advisory SYSS-2017-003 https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2017-003.txt [3] SySS Responsible Disclosure Policy https://www.syss.de/en/news/responsible-disclosure-policy/ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Credits: This security vulnerability was found by Dr. Adrian Vollmer of SySS GmbH. E-Mail: adrian.vollmer@syss.de Public Key: https://www.syss.de/fileadmin/dokumente/PGPKeys/Adrian_Vollmer.asc Key ID: 0x037C9FE7 Key Fingerprint: 70CF E88C AEE7 DB0F 5DC8 3403 0E02 7C7E 037C 9FE7 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Disclaimer: The information provided in this security advisory is provided "as is" and without warranty of any kind. Details of this security advisory may be updated in order to provide as accurate information as possible. The latest version of this security advisory is available on the SySS Web site. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Copyright: Creative Commons - Attribution (by) - Version 3.0 URL: http://creativecommons.org/licenses/by/3.0/deed.en -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEcM/ojK7n2w9dyDQDDgJ8fgN8n+cFAlilY6kACgkQDgJ8fgN8 n+ej0Q/+I8tOrdk6pqvJTY2CAG4NSvUiFxLLL9SpVMXjF/RsWUEsEEwV6RHYYLxx XNHXB1M1x+lJDA9gKoNDbwhqI6omcXFJvkfJeDnSDIpj09rfUZwFLqqjMjugmTtM 2AlRxYMd8HoIwwkfStul6veltRn7ty8Vl80TQvEF4dSzL/BENSqB/2LF0b4jx3bq 2OE+I7jnP+iS2RoQfQssnwTnjd1dHC8DSbiXzbzKkc5MFrYlW3Gm+aSdnCuhzx7t TvQ8JTivuhU5aoHfE1HB0cqNWq7ZkMN2oV05SkOsdrgLnX7AYFsdCJGy83L42SWT OBHmjncsvXr3Z7c5i8CqGnySdtvCUVDlsHu4uYnEGZhCVSe+prTwNEskRv5coVRg n/vw+TkLxaVOeqJMk188Cyl5l/jokOhVezdgiziv2R7ivclaAQrwKVgLKJd5DBMg LjuE6Aa0GFfpx5utH8fBeNsZhXBj4g0+H1UMEjgg+kn+aToDsGeZquTT2xYyglJg LVFVEPhA8F3H2aWgqEUQiuBDTOBCNglbxcuj42IPMqY5juZY/vERVU47uoz1RE4K UtWtTumUFVflE78Q06NXaszF0kwQ3uaUnB0BCf5plAe4UISnGjnhxNhbuAHDLD03 QNLDJ3RPnrXyPj0gxV2cfbitRHOf7CJOHrZqy/+lO1W7Y9Btryc= =sofz -----END PGP SIGNATURE-----