


Exploit of College Website v1.0 CMS - SQL injection

I couldn’t find a PoC for CVE-2023-30253, so I developed an effective one

Proof-of-concept exploit for a stored XSS vulnerability in Rafed CMS v1.44, demonstrating injection via the index.php parameter.

In Dolibarr 17.0.0 with the CMS Website plugin (core) enabled, an authenticated attacker can obtain remote command execution via php code injection…