Announcement

  •  » Miscellaneous
  •  » XSS-Warning in my https://carovanruit.de/piwigo/index.php

#1 2022-09-21 13:21:04

Caro van Ruit
Member
2022-09-21
1

XSS-Warning in my https://carovanruit.de/piwigo/index.php

Hello/Hi/Greetings,


I got an email from a Profiler who show me an xxs-attack

PiwiGo Version
Piwigo 12.3.0 Prüfen, ob eine neue Version verfügbar ist.
Betriebssystem: Linux
PHP: 7.3.13 (Info anzeigen) [2022-09-21 13:10:49]
MySQL: 5.7.25 [2022-09-21 13:10:49]
Grafikbibliothek: ImageMagick 6.8.9-9
Größe des Cache 105.79 Mo   berechnet vor 2 Tage Aktualisieren
Piwigo URL: https://carovanruit.de/piwigo/index.php

XSS-Warning in my piwigo


*parameter affected : https://carovanruit.de/piwigo/index.php/x

*payload : "><svG onLoad=prompt('xss')>

*link of xss vulnerable URL: https://carovanruit.de/piwigo/index.php … oad=prompt('xss')%3E/?/category/26=



the bug i find is cross site scripting(xss)

*description of the xss : one of the most popular attacks on the web, which is injected by your site with a script that executes malicious commands on the visitors' computers, meaning that your site becomes a means of catching the victims through a script planted by the hacker on your site.
In XSS, the hacker does not target your site at first, but rather uses it as a bridge to cross to the victims who are browsing it, exploiting a gap in your site that sneaks through your visitors to attack them

*Impact: If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user. Amongst other things, the attacker can:
Perform any action within the application that the user can perform.
View any information that the user is able to view.
Modify any information that the user is able to modify.
Initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user
stealing cookies

Offline

 
  •  » Miscellaneous
  •  » XSS-Warning in my https://carovanruit.de/piwigo/index.php

Board footer

Powered by FluxBB

github twitter newsletter Donate Piwigo.org © 2002-2024 · Contact