[建议描述] 发现 Sourcecodester Password Storage Application in PHP/OOP and MySQL 1.0 存在多个跨站脚本(XSS)漏洞, 涉及 Name、Username、Description 和 Site Feature 参数。
[附加信息] 概念验证:https://drive.google.com/file/d/1ZmAuKMVzUpL8pt5KXQJk8IyPECoVP9xw/view?usp=sharing 厂商主页:https://www.sourcecodester.com/php/15726/password-storage-application-phpoop-and-mysql-free-source-code.html 软件链接:https://www.sourcecodester.com/sites/default/files/download/oretnom23/psa_php.zip
[漏洞类型] 跨站脚本(XSS)
[产品厂商] Sourcecodester
[受影响产品代码库] Password Storage Application in PHP/OOP and MySQL - 1.0
[受影响组件] 源代码
[攻击类型] 远程
[影响代码执行] true
[攻击向量] 要利用此漏洞,攻击者需首先在 http://localhost/psa_php/owner_registration.php 注册账户,然后使用创建的密码登录。登录后,攻击者在 Name、Username、Description 和 Site 字段中注入任意 JavaScript 代码,并点击保存。一旦攻击者点击保存按钮,恶意 JavaScript Payload 将执行。
[参考] https://www.sourcecodester.com/php/15726/password-storage-application-phpoop-and-mysql-free-source-code.html https://drive.google.com/file/d/1ZmAuKMVzUpL8pt5KXQJk8IyPECoVP9xw/view?usp=sharing
[发现者] RashidKhan Pathan
使用 CVE-2022-43117