Advertisement






Themeqx Advanced PhP Laravel Classified ads cms - Cross-Site Scripting

CVE Category Price Severity
CVE-2021-37675 CWE-79 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2018-08-29
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N 0.02189 0.98644

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2018080216

Below is a copy:

Themeqx Advanced PhP Laravel Classified ads cms - Cross-Site Scripting
# Exploit Title: Themeqx Advanced PhP Laravel Classified ads cms - Cross-Site Scripting
# Google Dork: N/A
# Date: 2018-08-16
# Exploit Author: Ali Alipour
# WbeSite: Alipour.it
# Vendor Homepage: # Vendor Homepage: https://codecanyon.net/item/themeqx-advanced-php-laravel-classified-ads-cms/18221399
# Software Link Download : http://dl.20script.ir/script/service/Themeqx[www.20script.ir].zip
# Version: 2.0 
# Tested on: Kali Linux / Windows 10


# Proof of Concepts:
  
1. Go to the Target Website ( http://localhost/classifieds/ ) 
2- Select And Open Register Page [https://localhost/classifieds/user/create].
3- Create an account using your Email address .
4- Come back to site and Login using your Verified Mail and Password .
5- Go to Post an Ads Page (http://localhost/classifieds/dashboard/u/posts/create) .
6- Put the [ XSS ] parameter in the [ Ad description ] field .  

XSS parameter [ "><script>alert('Ali Alipour')</script> ]

7- Then click on the Save New Ad button . 

You will see a window of Ali AliPoor on your Ads pages

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum