Exploits / Vulnerability Discovered : 2023-07-28 |
Type : webapps |
Platform : php
This exploit / vulnerability Zomplog 3.9 crosssite scripting (xss) is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
Exploit Title: Zomplog 3.9 - Cross-site scripting (XSS)
Application: Zomplog
Version: v3.9
Bugs: XSS
Technology: PHP
Vendor URL: http://zomp.nl/zomplog/
Software Link: http://zomp.nl/zomplog/downloads/zomplog/zomplog3.9.zip
Date of found: 22.07.2023
Author: Mirabbas Ağalarov
Tested on: Linux
2. Technical Details & POC
========================================
steps:
1. Login to account
2. Add new page
3. Set as <img src=x onerror=alert(4)>
4. Go to menu