Lucene search

K
huntrUonghoangminhchauE2189AD5-B665-4BA5-B6C4-112E58AE9A97
HistoryAug 14, 2023 - 7:52 a.m.

XSS at file uploading

2023-08-1407:52:12
uonghoangminhchau
www.huntr.dev
14
file upload
cross-site scripting
web demo
add page
proof of concept
bug bounty

EPSS

0.001

Percentile

30.2%

Description

In menu Add page, there is a upload file function and xss payload can be injected there.

Detail:

1/ Access to the web demo and go to Add page menu.

2/ At upload file function, upload an file with filename is a payload xss.

3/ It will be triggered immediately.

Proof of Concept

Payload: "><img src>

Link video PoC: https://drive.google.com/file/d/1bgbbkTGhkKEYSVuQIyw58eKYjrW6pVc_/view?usp=sharing

EPSS

0.001

Percentile

30.2%

Related for E2189AD5-B665-4BA5-B6C4-112E58AE9A97