Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-48392 PoC — OrangeScrum 跨站脚本漏洞

Source
Associated Vulnerability
Title:OrangeScrum 跨站脚本漏洞 (CVE-2024-48392)
Description:OrangeScrum是美国OrangeScrum公司的一款简单但功能强大的免费开源项目管理软件。 OrangeScrum 2.0.11版本存在安全漏洞,该漏洞源于容易受到跨站脚本攻击,从而导致帐户接管。
Readme
# CVE-2024-48392 Exploit
## Overview
This repository contains a proof-of-concept (PoC) exploit for CVE-2024-48392, an XSS vulnerability discovered in Orangescrum self-hosted as well as the premium version. CVE ID: CVE-2024-48392
File Snapshot

[4.0K] /data/pocs/2961a6d031430a5355a258444869482a606ab473 ├── [ 847] poc.txt └── [ 229] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.