Skip to content

adiapera/xss_create2_boidcms_2.1.0

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 

Repository files navigation

XSS in BoidCMS 2.1.0 (/admin -> Create)

Software link: BoidCMS 2.1.0 [https://boidcms.github.io/#/] -> Download

@author: Antonio Díaz.

Description: Cross-site scripting (XSS) vulnerability in the Create section of the Admin Page of BoidCMS 2.1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Content' parameter.

CVE: CVE-2024-32343.

PoC

Admin Page -> Create (CVE-2024-32343)

  1. Enter to Create section of Admin Page, set the payload in 'Content' parameter and click on the Create button:

image image

  1. Show Dashboard page and click on the link to the new page you have created:

image image

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published