Exploit/Advisories no image

Published on November 18th, 2021 📆 | 1709 Views ⚑

0

Bludit 3.13.1 Cross Site Scripting – Torchsec


Text to Speech

# Exploit Title: Bludit 3.13.1 - 'username' Cross Site Scripting (XSS)
# Date: 19/10/2021
# Exploit Author: Vasu (tamilan_mkv)
# Vendor Homepage: https://www.bludit.com
# Software Link: https://www.bludit.com/releases/bludit-3-13-1.zip
# Version: bludit-3-13-1
# Tested on: kali linux
# CVE : CVE-2021-35323

### Steps to reproduce

1. Open login page http://localhost:800/admin/login;
2. Enter the username place ``admin">``and enter the password
3. Trigger the malicious javascript code





Source link

Tagged with:



Comments are closed.