Security
Headlines
HeadlinesLatestCVEs

Headline

Solar-Log 200 PM+ 3.6.0 Cross Site Scripting

Solar-Log 200 PM+ version 3.6.0 suffers from a persistent cross site scripting vulnerability.

Packet Storm
#xss#vulnerability#web#auth
# Exploit Title: Stored XSS in Solar-Log 200 3.6.0 web panel# Date: 10-30-23# Exploit Author: Vincent McRae, Mesut Cetin - Redteamer IT Security# Vendor Homepage: https://www.solar-log.com/en/# Version: Solar-Log 200 PM+ 3.6.0 Build 99 - 15.10.2019# Tested on: Proprietary devices: https://www.solar-log.com/en/support/firmware/# CVE: CVE-2023-46344# POC:1. Go to solar panel2. Go to configuration -> Smart Energy -> "drag & drop" button.3. Change "name" to: <xss onmouseenter="alert(document.cookie)"style=display:block>test</xss>4. Once you hover over "test", you get XSS -> if a higher privilegeduser hovers over it, we can get their cookies.

Packet Storm: Latest News

Grav CMS 1.7.44 Server-Side Template Injection