CVE-2022-33075
Exploit Title: Zoo Management System 1.0 - Stored Cross-Site-Scripting (XSS)
Date: 05/26/2022
Exploit Author: Angelo Pio Amirante
Version: 1.0
Tested on: Server: XAMPP
CVE: 2022-33075
Description:
Zoo Management System 1.0 is vulnerable to a stored cross site scripting in “Add Classification” functionality of the admin panel.
Exploit:
- Goto: http://localhost/admin/public_html/admin_login and login with the provided credentials
- Goto: http://localhost/admin/public_html/save_classification
- The “Classification Display Name” and “Classification Table Name” are both vulnerable so you can put in one of them
- Goto: http://localhost/admin/public_html/view_classifications
- Stored XSS payload is fired
Image Poc: