Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
#519 Added references attribute to cmseek findings
Signed-off-by: Ilyes Ben Dlala <ilyes.bendlala@iteratec.com>
  • Loading branch information
Ilyesbdlala committed Apr 18, 2023
commit 8cbec6b84d7649624489915554487f18bd83c1bd
37 changes: 37 additions & 0 deletions scanners/cmseek/parser/__snapshots__/parser.test.js.snap
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,16 @@ exports[`parser parses result of Joomla scan with core vulnerabilities successfu
"location": "http://172.26.0.3/",
"name": "PHPMailer Remote Code Execution Vulnerability",
"osi_layer": "APPLICATION",
"references": [
{
"type": "cve",
"value": "CVE-2016-10033",
},
{
"type": "url",
"value": "https://www.cve.org/CVERecord?id=CVE-2016-10033",
},
],
"severity": "HIGH",
},
{
Expand All @@ -35,6 +45,33 @@ exports[`parser parses result of Joomla scan with core vulnerabilities successfu
"location": "http://172.26.0.3/",
"name": "PPHPMailer Incomplete Fix Remote Code Execution Vulnerability",
"osi_layer": "APPLICATION",
"references": [
{
"type": "cve",
"value": "CVE-2016-10045",
},
{
"type": "url",
"value": "https://www.cve.org/CVERecord?id=CVE-2016-10045",
},
],
"severity": "HIGH",
},
{
"attributes": {
"joomla_version": "3.6.5",
"references": [
"https://www.rapid7.com/db/modules/exploit/multi/http/phpmailer_arg_injection",
"EDB : https://www.exploit-db.com/exploits/40969/",
],
},
"category": "Vulnerability",
"description": "Vulnerability of type PPHPMailer Incomplete Fix Remote Code Execution Vulnerability found",
"identified_at": "2021-09-22T10:29:01.721Z",
"location": "http://172.26.0.3/",
"name": "PPHPMailer Incomplete Fix Remote Code Execution Vulnerability",
"osi_layer": "APPLICATION",
"references": null,
"severity": "HIGH",
},
{
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,15 @@
"https://www.rapid7.com/db/modules/exploit/multi/http/phpmailer_arg_injection",
"EDB : https://www.exploit-db.com/exploits/40969/"
]
},
{
"name": "PPHPMailer Incomplete Fix Remote Code Execution Vulnerability **without CVE**",
"references": [
"https://www.rapid7.com/db/modules/exploit/multi/http/phpmailer_arg_injection",
"EDB : https://www.exploit-db.com/exploits/40969/"
]
}

],
"vulnerabilities_count": "2"
}
28 changes: 28 additions & 0 deletions scanners/cmseek/parser/parser.js
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,21 @@ async function parse(findings) {
let parsed_vulnerabilities = []
if (findings.vulnerabilities_count > 0) {
parsed_vulnerabilities = findings.vulnerabilities.map((vuln) => {
const cve = fetchCVE(vuln.references);
let references = null
if (cve) {
references = [
{
"type": "cve",
"value": cve
},
{
"type": "url",
"value": `https://www.cve.org/CVERecord?id=${cve}`
}
]
}

return {
name: vuln.name,
identified_at: last_scanned,
Expand All @@ -58,6 +73,7 @@ async function parse(findings) {
location: findings.url,
osi_layer: "APPLICATION",
severity: "HIGH",
references,
attributes: {
joomla_version: findings.joomla_version,
references: vuln.references,
Expand All @@ -68,4 +84,16 @@ async function parse(findings) {
// concat all parsed results
return parsed_vulnerabilities.concat(parsed_backupFiles).concat(parsed_debug_mode_enabled)
}
// Helper function to fetch CVE from references
// it is assumed that the reference is in the format "CVE : CVE-XXXX-XXXX"
function fetchCVE(references) {
for (const reference of references) {
if (reference.includes("CVE :")) {
const cve = reference.split("CVE : ")[1].trim();
return cve;
}
}
return null;
}

module.exports.parse = parse;