pakbch / File-Upload-XSS

File-Upload-XSS is a Python script that exploits the SVG XSS vulnerability in file upload services to gather information about users visiting a specific URL and send it to a Discord webhook.
17 stars 3 forks source link
discord file-upload stealer xss

Introduction

File-Upload-XSS is a Python script designed to take advantage of the SVG XSS vulnerability present in various file upload services. When a user visits the specified URL, the script gathers information about their visit and sends it to a Discord webhook for analysis.

Features

Preview

Script Menu

image

Grabbed Information

image

Demo

https://user-images.githubusercontent.com/98830093/209461303-408ae221-f883-4e5d-9291-3e4ea9147441.mp4

Updates

Added two new websites

Don't forget to add your Discord webhook URL in payload.js before running the script.