You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A stored XSS vulnerability exists in emlog pro 2.4.1 which allows attackers to execute arbitrary HTML code.
Details
Because /admin/link.php has CSRF problems, attackers can use XSS to cooperate with CSRF to attack.
The siteurl and icon parameters have XSS vulnerabilities.
Summary
A stored XSS vulnerability exists in emlog pro 2.4.1 which allows attackers to execute arbitrary HTML code.
Details
Because
/admin/link.php
has CSRF problems, attackers can use XSS to cooperate with CSRF to attack.The
siteurl
andicon
parameters have XSS vulnerabilities.POC
EXP:
A attacker put this exp in a server, When the admin users visit the html file,his cookie will be send to attackers.
The text was updated successfully, but these errors were encountered: