Skip to content

Gi0rgi0R/xss_installation_blackcat_cms_1.4.1

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 

Repository files navigation

XSS in BlackCat CMS install page

Software link: BlackCat CMS [https://blackcat-cms.org/]

Version: 1.4.1

@author: Jorge Riopedre

Description: BlackCat CMS 1.4.1 is affected by a Cross-site scripting (XSS) vulnerability in upload/install/index.php that allows remote attackers to inject arbitrary web script or HTML via the 'Website Title' parameter.

POC

When performing the installation and entering the site settings to install the appliance, the 'Website title' field is affected by the injection of arbitrary code:

imagen

imagen

About

XSS in install page in BlackCat CMS 1.4.1

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages