Advertisement
CVE | Category | Price | Severity |
---|---|---|---|
CVE-2019-12801 | CWE-79 | Not disclosed | Medium |
Author | Risk | Exploitation Type | Date |
---|---|---|---|
Giedrius Pocevicius | Medium | Remote | 2019-06-28 |
CVSS | EPSS | EPSSP |
---|---|---|
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | 0.02192 | 0.50148 |
# Exploit Title: [Persistent Cross-Site Scripting or Stored XSS in out/out.GroupMgr.php in SeedDMS before 5.1.11] # Google Dork: [NA] # Date: [17-June-2019] # Exploit Author: [Nimit Jain](https://www.linkedin.com/in/nimitiitk)(https://secfolks.blogspot.com) # Vendor Homepage: [https://www.seeddms.org] # Software Link: [https://sourceforge.net/projects/seeddms/files/] # Version: [< 5.1.11] (REQUIRED) # Tested on: [NA] # CVE : [CVE-2019-12801] Proof-of-Concept: Step 1: Login to the application and go to Groups Management in Admin tools. Step 2: Now create a new group as hello<script>alert("group")</script> Step 3: Now save it click on choose group to execute the javascript inserted above.
Copyright ©2024 Exploitalert.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.