Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-28715 | Kitploit
Tools/GitHubGitHub/lq0ne/cve-2024-28715
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHublq0ne/cve-2024-28715

CVE-2024-28715

View Repository
2 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-28715

[CVE ID]

CVE-2024-28715

[PRODUCT]

DoraCMS

[Version]

DoraCMS v2.18 and before

[PROBLEM TYPE]

Dom-based XSS.

[DESCRIPTION]

Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 function in the /app/public/apidoc/oas3/wrap-components/markdown.jsx endpoint.

[Usage]

https://[target-site]/static/apidoc/index.html?url=https://[your-site]/POC.yaml

Download Tool