[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Submitty 20.04.01 - Persistent Cross-Site Scripting Vulnerability

Author
humblelad
Risk
[
Security Risk High
]
0day-ID
0day-ID-34453
Category
web applications
Date add
19-05-2020
CVE
CVE-2020-12882
Platform
php
# Exploit Title: Submitty 20.04.01 - Persistent Cross-Site Scripting
# Exploit Author: humblelad
# Vendor Homepage: http://submitty.org/
# Software Link: https://github.com/Submitty/Submitty/releases
# Version: 20.04.01
# Tested on: Mac Os Catalina
# CVE : CVE-2020-12882


Description:
Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated
by an attack by a Student against a Teaching Fellow.This vulnerability can potentially enable any student to takeover the account of TA if they open the attachment as the cookie gets exposed.

1.As student login, via student:student

2.Go here http://localhost:1501/s20/tutorial/gradeable/01_simple_python (as ex.)

3.In the new submission upload the  malicious .svg file with any xss payload.

	

Login as ta and open the same for grading. The XSS gets triggered alerting the cookies.

#  0day.today [2024-11-16]  #