Exploits / Vulnerability Discovered : 2023-07-21 |
Type : webapps |
Platform : php
This exploit / vulnerability Perch v3.2 stored xss is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
Exploit Title: Perch v3.2 - Stored XSS
Application: Perch Cms
Version: v3.2
Bugs: XSS
Technology: PHP
Vendor URL: https://grabaperch.com/
Software Link: https://grabaperch.com/download
Date of found: 21.07.2023
Author: Mirabbas Ağalarov
Tested on: Linux
2. Technical Details & POC
========================================
steps:
1. login to account
2. go to http://localhost/perch_v3.2/perch/core/settings/
3. upload svg file