Skip to content

anh91/Camaleon-CMS-XSS-

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 

Repository files navigation

Description: Camaleon CMS v2.7.4 was discovered to contain a Cross Site Scripting (store XSS).

Affected Component: All versions that are below 2.7.4

Step to reproduce: Detection and Exploitation: 1. Go to Add page

2.Inject payload : "' test <img src="" onerror="alert(1)"> to Title and save draft it

Go to list post save draft include a malicious payload. Then the script is execute

POC:

image image

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors