Local services search engine management system (lssmes) 1.0 name persistent crosssite scripting (xss) Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2021-03-03 |
Type : webapps |
Platform : php
This exploit / vulnerability Local services search engine management system (lssmes) 1.0 name persistent crosssite scripting (xss) is for educational purposes only and if it is used you will do on your own risk!
*Steps to Reproduce:*
1) Login with Admin Credentials and click on the *Person List* button.
2) Click on the *Add Person* button.
3) Now add the 'Ba1man' in the input field of *Name* and 'Ba2man' in the input field of *Address *then intercept it with Burp Suite.
4) Now add the following payload input field of *Name & Address*.
4) Click On Add
5) Now go to http://localhost/LSSMES/lssems/view-category-detail.php?viewid=3
6) XSS payload is triggered.
7) Secondly, go to http://localhost/LSSMES/lssems/single-person-detail.php?viewid=25
8) Again XSS payload is triggered