Lucene search

K
huntrScgajge1214941381-B669-4756-94FC-CCE172472F8B
HistoryJul 22, 2023 - 5:24 a.m.

Stored XSS in title

2023-07-2205:24:39
scgajge12
www.huntr.dev
16
stored xss
admin screen
item title
executed script

EPSS

0.001

Percentile

23.8%

Description

There is Stored XSS in the item title of the menu on the administrator screen.

Proof of Concept

Step 1. Log in to the admin screen and select Add New Item in Menu.
Step 2. Specify the following Payload for the item title and save it.
Step 3. Once saved, any script can be executed on the administrator screen.

Payload

<img src>

Request

POST /admin/menu/item_add/1/40 HTTP/2
Host: localhost
 ...
-----------------------------270651214445377498288823999
Content-Disposition: form-data; name="title"

<img src>
-----------------------------270651214445377498288823999
 ...

PoC Video

https://drive.google.com/file/d/1DjT6hbPBXpIs2pbrZ1EZZluZDOSDjeMk/view?usp=sharing

EPSS

0.001

Percentile

23.8%

Related for 14941381-B669-4756-94FC-CCE172472F8B