关联漏洞
介绍
# CVE-2024-27665
Unifiedtransform v2.X is vulnerable to Stored Cross-Site Scripting (XSS) via file upload feature in Syllabus module.
Vendor: https://github.com/changeweb/Unifiedtransform
---
## PoC
Step 1: Log in to the Application and Navigate to Academic module.

Step 2: Create Session,Semester,Class,Course from the Academic module with random data.
Step 3: Navigate to Syllabus module, fill in the required details and upload [PDF file](https://github.com/Thirukrishnan/CVE-2024-27665/blob/main/xss.pdf) with XSS payload in the Syllabus File upload input.

Step 4: Navigate to Classes -> Syllabus and click on download.


Step 5: Observe the XSS getting triggered!.

文件快照
[4.0K] /data/pocs/442f3a8016eaf1bb37e931da62c7c65261d3a178
├── [1.2K] README.md
└── [127K] xss.pdf
0 directories, 2 files
备注
1. 建议优先通过来源进行访问。
2. 如果因为来源失效或无法访问,请发送邮件到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
3. 神龙已为您对 POC 代码进行快照,为了长期维护,请考虑为本地 POC 付费/捐赠,感谢您的支持。