Cloudron 6.2 – ‘returnTo ‘ Cross Site Scripting (Reflected)

  • 作者: Akıner Kısa
    日期: 2021-09-22
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/50317/
  • # Exploit Title: Cloudron 6.2 - 'returnTo ' Cross Site Scripting (Reflected)
    # Date: 10.06.2021
    # Exploit Author: Akıner Kısa
    # Vendor Homepage: https://cloudron.io
    # Software Link: https://www.cloudron.io/get.html
    # Version: 6.3 >
    # CVE : CVE-2021-40868
    
    
    Proof of Concept:
    
    1. Go to https://localhost/login.html?returnTo=
    2. Type your payload after returnTo=
    3. Fill in the login information and press the sign in button.