Skip to content

KielVaughn/CVE-2021-38603

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 
 
 

Repository files navigation

CVE-2021-38603

A stored cross site scripting vulnerability is present on the Profile edit page in the Information: field for each user.

http://<hostname/server ip>/core/admin/profil.php

Vulnerable Fields:

  • Information:

User Profile Page

Once inserted, XSS can be triggered by visiting any page/article created by that particular user.

Profile XSS

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published