Exploits / Vulnerability Discovered : 2020-01-08 |
Type : webapps |
Platform : php
This exploit / vulnerability Codoforum 4.8.3 input_txt persistent crosssite scripting is for educational purposes only and if it is used you will do on your own risk!
Codoforum is prone to a Persistent Cross-site Scripting Vulnerability in User-Comment replay section
An attacker can exploit this issue to creating user with payload and perform cross-site scripting attacks.
Codoforum version 4.8.3 is vulnerable.
1. Install Codoforum 4.8.3 in a local server.
2. Go to Start a new Topic >> Replay to any of the comment with XSS Payload
3. Payload : "><svg/onload=alert(1)>
4. Now an XSS alert will be triggered here.