paintballrefjosh/MaNGOSWebV4 < 4.0.8 contains a reflected XSS caused by unsanitized input in install/index.php (step parameter), letting attackers execute arbitrary scripts in the victim's browser, exploit requires victim to visit a maliciously crafted URL
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view