Skip to content

anh91/xss-camaleon-cms

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 

Repository files navigation

Description: Camaleon CMS v2.7.4 was discovered to contain a Cross Site Scripting (store XSS).

Affected Component: All versions that are below 2.7.4

Step to reproduce : Detection and Exploitation: 1.Go to Add Category

2.Inject payload : "' test <img src="" onerror="alert(1)"> to name of category and save it

  1. Go to list post and create a new post with a category that include a malicious payload. Then script is execute

  2. Go to link of post then script is execute

poc:

image

image

image

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published