Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-1304---Badgermeter-moni-tool-Reflected-Cross-Site-Scripting-XSS — POC Badgermeter moni tool - CVE-2024-1304 | Kitploit
Tools/GitHubGitHub/guillermogm4/cve-2024-1304---badgermeter-moni-tool-reflected-cross-site-scripting-xss
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubguillermogm4/cve-2024-1304---badgermeter-moni-tool-reflected-cross-site-scripting-xss

CVE-2024-1304---Badgermeter-moni-tool-Reflected-Cross-Site-Scripting-XSS

POC Badgermeter moni tool - CVE-2024-1304

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
2 years agoNot yet reviewed

CVE-2024-1304 --- Badgermeter moni tool - Reflected Cross Site Scripting XSS

https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-badger-meters-monitool

CVE-2024-1304: 6.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L | CWE-79.

Software link: https://www.s-can.at/en/product/monitool/

Version: 4.6.3

@author: Guillermo García Molina

Description: The software s:can moni:tools up to and including version 4.6.3 is affected by an unauthenticated reflected cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the url.

POC

The root url of the device, in this case http://192.168.0.1/, is affected by an unauthenticated injection of arbitrary code:

[http://192.168.0.1//sunkul36qj ]

XSS1

image

Download Tool