
Proof-of-concept repository documenting a stored XSS vulnerability in Sourcecodester Password Storage Application 1.0, with exploit details and attack vectors for security testing.
[推奨説明] Sourcecodester Password Storage Application in PHP/OOP and MySQL 1.0 には、Name、Username、Description、Site Feature パラメーターを介した 複数のクロスサイトスクリプティング(XSS)脆弱性が存在することが判明しました。
[追加情報] Proof Of Concept: https://drive.google.com/file/d/1ZmAuKMVzUpL8pt5KXQJk8IyPECoVP9xw/view?usp=sharing Vendor Homepage: https://www.sourcecodester.com/php/15726/password-storage-application-phpoop-and-mysql-free-source-code.html Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/psa_php.zip
[脆弱性タイプ] クロスサイトスクリプティング (XSS)
[製品ベンダー] Sourcecodester
[影響を受ける製品コードベース] Password Storage Application in PHP/OOP and MySQL - 1.0
[影響を受けるコンポーネント] Source Code
[攻撃タイプ] Remote
[影響:コード実行] true
[攻撃ベクトル] この脆弱性を悪用するには、攻撃者はまず http://localhost/psa_php/owner_registration.php で自身のアカウントを作成し、作成したパスワードでログインする必要があります。ログイン後、攻撃者は Name、Username、Description、Site フィールドに任意の JavaScript コードを注入し、保存をクリックします。保存ボタンをクリックすると、任意の JavaScript ペイロードが実行されます。
[参考] https://www.sourcecodester.com/php/15726/password-storage-application-phpoop-and-mysql-free-source-code.html https://drive.google.com/file/d/1ZmAuKMVzUpL8pt5KXQJk8IyPECoVP9xw/view?usp=sharing
[発見者] RashidKhan Pathan
Use CVE-2022-43117