Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-48589 — Proof-of-concept for CVE-2024-48589, a stored/reflected XSS vulnerability in phpAbook 9.0i via the `rol` parameter and path section, enabling arbitrary JavaScript injection and session cookie disclosure. | Kitploit
Tools/GitHubGitHub/exek1el/cve-2024-48589
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubexek1el/cve-2024-48589

CVE-2024-48589

Proof-of-concept for CVE-2024-48589, a stored/reflected XSS vulnerability in phpAbook 9.0i via the `rol` parameter and path section, enabling arbitrary JavaScript injection and session cookie disclosure.

View Repository
11 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

phpAbook 9.0i - Cross-Site Scripting (XSS) Vulnerability (CVE-2024-48589)


Summary:

A Cross-Site Scripting (XSS) vulnerability was discovered in the rol parameter of index.php or the path section in the phpAbook application. This vulnerability allows an attacker to inject arbitrary JavaScript code into a user's browser, potentially leading to:

  • Disclosure of sensitive information, including session cookies
  • Unauthorized actions within the application context

The issue arises due to improper validation and sanitization of user-supplied input.


Impact:

An attacker can craft a URL with a malicious script in the rol parameter or path section and trick a user into visiting the link or execute the link directly in the browser.


Proof of Concept (PoC):

Access the index.php page of the phpabook application.

Append an XSS payload to the index.php URL. For example:

/abc"><script>alert(document.domain)</script>

Another vulnerable parameter is rol, which can be found in the "Show All" tab.

Inject the XSS payload into the rol parameter. For example:

rol=abc"><script>alert(document.domain)</script>

Download Tool