Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-33408 — Proof-of-concept demonstrating stored cross-site scripting (XSS) in Minical 1.0.0 via the Room Status edit note feature, with step-by-step reproduction instructions. | Kitploit
Tools/GitHubGitHub/thirukrishnan/cve-2023-33408
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubthirukrishnan/cve-2023-33408

CVE-2023-33408

Proof-of-concept demonstrating stored cross-site scripting (XSS) in Minical 1.0.0 via the Room Status edit note feature, with step-by-step reproduction instructions.

View Repository
13 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-33408

Minical 1.0.0 is vulnerable to Stored Cross-Site Scripting (XSS)

Vendor: https://github.com/minical/minical
Demo Application: https://demo.minical.io/


PoC

Step 1: Log in to the Minical Application and Navigate to Room->Room Status.

image

Step 2: Click on the Edit Room Note option and enter the payload.
Payload= <svg onload=alert(document.location)<!--

image

Step 3: Click on Save Changes and observe the payload getting triggered.

image

image

Download Tool