Haraj Script 3.7 - DM Section Authenticated Stored XSS# CVE-2022-31300
Haraj Script 3.7 - DM Section Authenticated Stored XSS
#### Exploit Title: Haraj Script 3.7 - Authenticated Stored XSS
#### Date: 2022-06-13
#### CVE: CVE-2022-31300
#### Exploit Author: Abdulaziz Saad (@b4zb0z)
#### Vendor Homepage: https://angtech.org/
#### Software Link: https://angtech.org/product/view/3
#### Version: 3.7
#### Tested on: LAMP, Ubuntu
---
[#] Exploitation :
exploit DM messages section with js payload by manipluating and repeating sent request via Burpsuite or DevTools
[4.0K] /data/pocs/b15e217d6ee7d3a9d78da978cf72bc33be1b33e2
└── [ 514] README.md
0 directories, 1 file