Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-43032 — Post authenticated stored-xss in XenForo versions ≤ 2.2.7 | Kitploit
Tools/GitHubGitHub/sakurasamuraii/cve-2021-43032
Phishing ToolsVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubsakurasamuraii/cve-2021-43032

CVE-2021-43032

Post authenticated stored-xss in XenForo versions ≤ 2.2.7

View Repository
2254 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-43032

In XenForo ≤ 2.2.7, a threat actor with access to the admin panel can save cross-site scripting payloads in any function within the application that accepts HTML code. A payload placed within the 'Advertising' functionality will execute globally on the client side, allowing for multiple exploitation scenarios, whereas other payloads will execute on the clientside depending on where it was stored.

Credits: John Jackson @johnjhacking & Jackson Henry @JacksonHHax

Steps to Replicate

  1. Login to the admin panel located at /admin.php Admin Panel
  2. Create a new advertisement and store the payload within the HTML body. Advertisement PoC
  3. Navigate to the clientside and you'll see the alert popup universally across the application. Alert 1
  4. You can store scripts that will execute in varying parts of the application. As another example, here is the process of storing malicious script in the node functionality. Node PoC
  5. Going to the clientside and navigating to the particular node results in execution. Alert 2

Impact

The biggest risk with this vulnerability would be an ill-intended user executing covert actions embeded in extensive HTML pages, such as mining cryptocurrency or exfiltrating data. This could be a user with pre-existing access to the application, or a threat actor that obtains credentials via account takeover or social engineering methodology.

Download Tool