Hoşgeldin Misafir

Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting Vulnerability

NasyoneL

NasyoneL

Karanlık Özgürlüktür
25 Ağu 2017
25,060 Mesaj

Aktiflik

Seviye

Deneyim

TIM / GÖREV:
Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting Vulnerability

Kod:
# Exploit Title: Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting
# Exploit Author: Sayak Naskar
# Vendor Homepage: https://vanillaforums.com/en/
# Version: 2.6.3
# Tested on: Windows, Linux
# CVE : CVE-2020-8825
 
A Stored xss was found in Vanillaforum 2.6.3 .
 
index.php?p=/dashboard/settings/branding
 
# Proof of Concept:
 
An attacker will insert a payload on branding section. So, whenever an user will open the branding section then attacker automatically get all sensitive information of the user.
 
#  0day.today [2020-02-12]  #