Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-38875 PoC — PHP-Login-System 跨站脚本漏洞

Source
Associated Vulnerability
Title:PHP-Login-System 跨站脚本漏洞 (CVE-2023-38875)
Description:PHP-Login-System是一个Web应用。 PHP-Login-System 2.0.1版本存在安全漏洞,该漏洞源于允许远程攻击者通过将恶意负载包含到/reset中的validator参数中,在用户的 Web 浏览器中执行任意 JavaScript -密码 。
Description
msaad1999's PHP-Login-System 2.0.1 contains a reflected cross-site scripting caused by unsanitized input in 'validator' parameter in /reset-password, letting remote attackers execute arbitrary JavaScript in a user's browser, exploit requires attacker to craft malicious URL
File Snapshot

id: CVE-2023-38875 info: name: PHP Login System 2.0.1 - Cross-Site Scripting author: 0x_Akoko ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.