Skip to content

anh91/Camaleon-xss

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 

Repository files navigation

Description: Camaleon CMS v2.7.4 was discovered to contain a Cross Site Scripting (store XSS).

Affected Component: All versions that are below 2.7.4

Step to reproduce: Detection and Exploitation:

  1. Go to seting content group

2.Inject payload : "' test <img src="" onerror="alert(1)"> to name of post type

  1. Access to admin page. Then the script is execute

POC:

image

image

image

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published