Last active
June 10, 2020 22:06
-
-
Save kdrypr/5dac91c2d27c4dc82b1225dffa38f7a8 to your computer and use it in GitHub Desktop.
Your Online Shop XSS Vulnerability
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
I found stored XSS vulnerability in userarea Name Surname field. You can exploit with this payload <img src='aa' onerror='javascript:alert(1)' > | |
write in surname field. | |
https://i.imgur.com/Pj1A5bE.png | |
App Link: https://youronlineshop.sourceforge.io/sample/?userarea=1 | |
Download link: https://sourceforge.net/projects/youronlineshop/ | |
Version: 1.8.0 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment