Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2020-9460 — Proof-of-concept for a stored cross-site scripting (XSS) vulnerability in Octech Oempro 4.7–4.11 via the CampaignName parameter in Campaign.Create. | Kitploit
Tools/GitHubGitHub/g-rubert/cve-2020-9460
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubg-rubert/cve-2020-9460

CVE-2020-9460

Proof-of-concept for a stored cross-site scripting (XSS) vulnerability in Octech Oempro 4.7–4.11 via the CampaignName parameter in Campaign.Create.

View Repository
116 years agoNot yet reviewed
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2020-9460

root@kitploit:~
██╗  ██╗███████╗███████╗
╚██╗██╔╝██╔════╝██╔════╝
 ╚███╔╝ ███████╗███████╗
 ██╔██╗ ╚════██║╚════██║
██╔╝ ██╗███████║███████║
╚═╝  ╚═╝╚══════╝╚══════╝

Cross Site Scripting - Oempro

Octech Oempro 4.7 through 4.11 allow XSS by an authenticated user. The parameter CampaignName in Campaign.Create is vulnerable.

Command:Campaign.Create

Request parameter:CampaignName

Version: Oempro v4.7 <= v4.11

Researcher: Guilherme Rubert

Payload:

root@kitploit:~
"><marquee/onstart=alert("XSS")>


References:

https://guilhermerubert.com/blog/cve-2020-9460/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9460

https://nvd.nist.gov/vuln/detail/CVE-2020-9460

https://www.octeth.com/

Download Tool