Xoops CMS 2.5.10 Cross Site Scripting

CVE Category Price Severity
CVE-2021-3502 CWE-79 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2023-06-14
Our sensors found this exploit at:

Below is a copy:

Xoops CMS 2.5.10 Cross Site Scripting
# Exploit Title: Xoops CMS Version 2.5.10 - Stored Cross-Site Scripting (XSS) (Authenticated)
# Date: 2023-06-12
# Exploit Author: tmrswrr
# Vendor Homepage:
# Software
# Version: 2.5.10
# Tested :

--- Description ---

1) Login admin panel and click Image Manager , choose Add Category :
2) Write your payload in the Category Name field and submit:
Payload: <script>alert(1)</script>
3) After click multiupload , when you move the mouse to the payload name, you will see the alert button

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.