[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Bakeshop Online Ordering System 1.0 - (Owner) Persistent Cross-site scripting Vulnerability

Author
Parshwa Bhavsar
Risk
[
Security Risk High
]
0day-ID
0day-ID-35378
Category
web applications
Date add
02-12-2020
Platform
multiple
# Exploit Title: Bakeshop Online Ordering System 1.0 - 'Owner' Persistent Cross-site scripting
# Exploit Author: Parshwa Bhavsar
# Vendor Homepage: https://www.sourcecodester.com/
# Software Link: https://www.sourcecodester.com/php/14609/bakeshop-online-ordering-system-phpmysqli-full-source-code.html
# Version: 1.0
# Tested on: Windows 10/XAMPP

Payload : "><img src=x onerror=alert(1)>


Steps to Reproduce :-

1. Login in admin dashboard & Click on 'Categories'.
2. You will notice the "New" button ,Click on that and You will notice the "Category" input field.
3. Put  XSS Payload on that field and save it.
4. XSS will be triggered.

#  0day.today [2024-11-16]  #