Exploit/Advisories

Published on January 11th, 2021 📆 | 4173 Views ⚑

0

Resumes Management and Job Application Website 1.0 – Multiple Stored XSS


iSpeech.org

# Exploit Title: Resumes Management and Job Application Website 1.0 - Multiple Stored XSS
# Date: 2/1/2021
# Exploit Author: Saswat Subhajyoti Mallick
# Vendor Homepage: https://egavilanmedia.com/
# Software Link: https://egavilanmedia.com/resumes-management-and-job-application-website/
# Version: 1.0
# Tested on: windows 10/wamp

Attacker can put stored xss and gain admin access unauthenticated .
For stored XSS poc simply put  in first name,last name and address field while applying for resume.

Stored XSS will be activated the moment admin user logs in.
            





Source link

Tagged with:



Comments are closed.