CVE-2022-31897
日期:06/22/2022
漏洞作者:Angelo Pio Amirante
版本:1.0
测试环境:服务器:Windows 10 上的 XAMPP
CVE编号:CVE-2022-31897
描述:
Zoo Management System 1.0 在注册页面存在反射型跨站脚本漏洞。'http://localhost/public_html/register_visitor?msg='中的"msg"参数存在漏洞。
影响:
攻击者可以通过向受害者发送精心构造的URL来窃取Cookie。
利用:
访问以下页面:
-
http://localhost/public_html/register_visitor?msg=
-
弹窗触发!
截图POC: