Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

XSS upload file to *.SVG in Zenario CMS 9.0.54156 #1

Closed
hieuminhnv opened this issue Sep 30, 2021 · 0 comments
Closed

XSS upload file to *.SVG in Zenario CMS 9.0.54156 #1

hieuminhnv opened this issue Sep 30, 2021 · 0 comments

Comments

@hieuminhnv
Copy link
Owner

Summary
hi team,
I found small XSS upload file to SVG.

Info

  1. Zenario CMS 9.0.54156 last version
  2. FireFox 92.0.1 (64-bit)

image

Steps

  1. Login to account http://xxx.xxx.x.x/admin.php?cID=1&cType=html

image

  1. Choose Users & Contacts and create any user
  2. Click Image >> Upload an image

image
4. use burpsuite and capture request file a.svg

image
5. click to image avatar >> click right mouse >> Inspect Element (F12) >> found to link vlun svg

image

  1. Copy domain >> open web >> BOOM XSS alert message

image

Inpact :
Attacker can send malicious files to victims and steals victim's cookie leads to account takeover.
The person viewing the image of a contact can be victim of XSS.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant