Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[bug]Elefant CMS 2 beta 1.3.6 Persistent XSS vulnerability #217

Closed
AnonFreeworld opened this issue Feb 27, 2014 · 1 comment
Closed

[bug]Elefant CMS 2 beta 1.3.6 Persistent XSS vulnerability #217

AnonFreeworld opened this issue Feb 27, 2014 · 1 comment

Comments

@AnonFreeworld
Copy link

Dork: "Powered by elefant cms 1.3.6"

Affected:
https://github.com/jbroadway/elefant/archive/elefant_1_3_6_beta.tar.gz

Other versions haven't been tested.

Brief Summary:
In order to exploit this vulnerability you must go to the blog of the targeted site. Create an account and sign in. Once signed in you change your username to the payload you are wishing to use. Ex: <script>alert("Hacked");</script>

POC:
http://prntscr.com/2w7krs

Hope this helps and is fixed - Anon

@jbroadway
Copy link
Owner

Thanks for the head's up!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants