Hebing123 / cve

0 stars 0 forks source link

DBShop商城系统 V 3.3 Release 231225 has a reflective XSS vulnerability #31

Open Hebing123 opened 5 months ago

Hebing123 commented 5 months ago

Summary

A reflected XSS (Cross-Site Scripting) vulnerability has been discovered in DBShop商城系统 V 3.3 Release 231225. The vulnerability allows for the execution of arbitrary HTML/javascript code, potentially resulting in the theft of sensitive user information.

Details

The vulnerability is located in My Orders in the User Center. $orderStatus is echoed directly on the page without filtering. image

Proof of Concept (POC)

http(s)://your-ip/home-order?orderStatus=%22%3E%3Csvg%20onload=alert(5888)%3E image

Hebing123 commented 4 months ago

No CVE number is assigned.