Exploits / Vulnerability Discovered : 2020-12-16 |
Type : webapps |
Platform : php
This exploit / vulnerability Grav cms 1.6.30 admin plugin 1.9.18 page title persistent crosssite scripting is for educational purposes only and if it is used you will do on your own risk!
1) log in to the grav-admin panel
2) Go to Pages
3) Click on Add
4) It will ask to Add Page
5) fill the following details as below
Page Title : <script>alert(1337)</script>
Folder Name : sagar_Banwa
Parent Page : /(root)
Page Template : Default
Value : yes
6) click on the Save button
7) now Click on Pages again.
8) your page name will be listed as <script>alert(1337)</script>
9) Now click on the eye button to see the XSS or you can simply go to http://127.0.0.1/grav-admin/ the XSS will pop-up