[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Bludit 3.13.1 - (username) Cross Site Scripting Vulnerability

Author
Vasu
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-37052
Category
web applications
Date add
17-11-2021
CVE
CVE-2021-35323
Platform
php
# Exploit Title: Bludit 3.13.1 - 'username' Cross Site Scripting (XSS)
# Exploit Author: Vasu (tamilan_mkv)
# Vendor Homepage: https://www.bludit.com
# Software Link: https://www.bludit.com/releases/bludit-3-13-1.zip
# Version: bludit-3-13-1
# Tested on: kali linux
# CVE : CVE-2021-35323

### Steps to reproduce

1. Open login page http://localhost:800/admin/login;
2. Enter the username place ``admin"><img src=x onerror=alert(1)>``and enter the password
3. Trigger the malicious javascript code

#  0day.today [2024-11-15]  #