Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
Change Mirror[12] Download[13]
# Exploit Title: FleetCart 4.1.1 - WebPage Content Information Disclosure
# Exploit Author: CraCkEr
# Date: 13/05/2024
# Vendor: EnvaySoft
# Vendor Homepage: https://codecanyon.net/item/fleetcart-laravel-ecommerce-system/23014826
# Software Demo Link: https://demo.fleetcart.envaysoft.com/en
# Tested on: Windows 11 Pro 22H2
# Impact: Sensitive Information Leakage
# CWE: CWE-200 - CWE-284 - CWE-266
# CVE: CVE-2024-5230
# CAPEC: CAPEC-19 / CAPEC-116
# ATT&CK: T1592
## Description
Issues with information disclosure in redirect responses. Accessing the majority of the website's pages exposes sensitive data, including the "Razorpay" "razorpayKeyId".
## Steps to Reproduce:
When you view the majority of the pages on the website, such as
https://demo.fleetcart.envaysoft.com/en/login
https://demo.fleetcart.envaysoft.com/en/categories/smartphones/products
https://demo.fleetcart.envaysoft.com/en/products?query=123
There is information leaking in the body page response.
+---------------------+
razorpayKeyId: 'rzp_test_oACp03vDsqdixc',
+---------------------+
Note: the same leaked "razorpayKeyId" is added to "Razorpay" in the Administration Panel.
on this Path:
https://demo.fleetcart.envaysoft.com/en/admin/settings?tab=razorpay (Login as Administrator)
[-] Done
File Tags
- ActiveX[19] (933)
- Advisory[20] (85,362)
- Arbitrary[21] (16,708)
- BBS[22] (2,859)
- Bypass[23] (1,835)
- CGI[24] (1,032)
- Code Execution[25] (7,686)
- Conference[26] (689)
- Cracker[27] (844)
- CSRF[28] (3,375)
- DoS[29] (24,752)
- Encryption[30] (2,383)
- Exploit[31] (52,907)
- File Inclusion[32] (4,255)
- File Upload[33] (987)
- Firewall[34] (822)
- Info Disclosure[35] (2,864)
- Intrusion Detection[36] (910)
- Java[37] (3,128)
- JavaScript[38] (891)
- Kernel[39] (7,067)
- Local[40] (14,726)
- Magazine[41] (586)
- Overflow[42] (13,105)
- Perl[43] (1,434)
- PHP[44] (5,209)
- Proof of Concept[45] (2,374)
- Protocol[46] (3,707)
- Python[47] (1,617)
- Remote[48] (31,479)
- Root[49] (3,620)
- Rootkit[50] (523)
- Ruby[51] (620)
- Scanner[52] (1,650)
- Security Tool[53] (7,994)
- Shell[54] (3,261)
- Shellcode[55] (1,217)
- Sniffer[56] (901)
- Spoof[57] (2,266)
- SQL Injection[58] (16,548)
- TCP[59] (2,428)
- Trojan[60] (689)
- UDP[61] (900)
- Virus[62] (669)
- Vulnerability[63] (32,756)
- Web[64] (9,906)
- Whitepaper[65] (3,776)
- x86[66] (967)
- XSS[67] (18,199)
- Other[68]
File Archives
- May 2024[69]
- April 2024[70]
- March 2024[71]
- February 2024[72]
- January 2024[73]
- December 2023[74]
- November 2023[75]
- October 2023[76]
- September 2023[77]
- August 2023[78]
- July 2023[79]
- June 2023[80]
- Older[81]
Systems
- AIX[82] (429)
- Apple[83] (2,088)
- BSD[84] (376)
- CentOS[85] (58)
- Cisco[86] (1,927)
- Debian[87] (7,042)
- Fedora[88] (1,693)
- FreeBSD[89] (1,246)
- Gentoo[90] (4,499)
- HPUX[91] (880)
- iOS[92] (375)
- iPhone[93] (108)
- IRIX[94] (220)
- Juniper[95] (69)
- Linux[96] (49,754)
- Mac OS X[97] (691)
- Mandriva[98] (3,105)
- NetBSD[99] (256)
- OpenBSD[100] (488)
- RedHat[101] (15,892)
- Slackware[102] (941)
- Solaris[103] (1,611)
- SUSE[104] (1,444)
- Ubuntu[105] (9,512)
- UNIX[106] (9,403)
- UnixWare[107] (187)
- Windows[108] (6,660)
- Other[109]
- Services
- Security Services[120]
- Hosting By
- Rokasec[121]


