Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!
CVE-2023-30212-POC — Proof-of-concept exploit for CVE-2023-30212, an XSS vulnerability in Ourphp 7.2.0, including Docker setup and payload demonstration. | Kitploit
step 6. Setup Ourphp on browser Open your browser and enter localhost or 127.0.0.1 Follow the instruction and install Ourphp
step7. Exploiting the vulnerability Ourphp 7.2.0 version has a vulnerability to XSS (Cross-Site Scripting). To mitigate the vulnerability in the /client/manage /ourphp_out.php file that allows for the execution of XSS code
you need to modify the code. The vulnerability arises when the "ourphp_admin" parameter is set to "logout," and the controllable variable is "out"