Headline
Blood Donor Management System 1.0 Cross Site Scripting
Blood Donor Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
# Exploit Title: Blood Donor Management System - Stored XSS# Application: Blood Donor Management System# Version: v1.0 # Bugs: Stored XSS# Technology: PHP# Vendor Homepage: https://phpgurukul.com/# Software Link: https://phpgurukul.com/blood-donor-management-system-using-codeigniter/# Date: 15.08.2023# Author: Ehlullah Albayrak# Tested on: Windows#POC========================================1. Login to user account2. Go to Profile 3. Change "State" input and add "<script>alert("xss")</script>" payload.4. Go to http://localhost/blood/welcome page and search "O", XSS will be triggered.#Payload: <script>alert("xss")</script>