Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-43142: BugReport/XssBug.md at main · TongJinBo/BugReport

A cross-site scripting (XSS) vulnerability in the add-fee.php component of Password Storage Application v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter.

CVE
#xss#vulnerability#web#php

Permalink

1 contributor

Users who have contributed to this file

Bug Submitter: 佟金波

Password Storage Application v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the add-fee.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter.

  1. vendors: sourcecodester.com;

  2. Vulnerability location: /psa_php/api.php?action=save

[+] Payload:

"><script>alert(1)</script>

Please execute the Payload provided above, as shown in the following figure:

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda