Closed msegoviag closed 9 months ago
Hi @msegoviag, Thank you for taking the time to create this issue and for contributing to this project 🍻
I have updated the template and made a few changes, such as removing the demo directory. This is because the users are expected to provide the full path to the CMS, and it won't be hosted inside that directory on real targets. Thanks
You can join our discord server. It's a great place to connect with fellow contributors and stay updated with the latest developments. Thank you once again
Note: Please refrain from sharing vulnerable environments on GitHub. You can do so via Discord DM for template validation.
Template Information:
Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the Demo 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.
POC
[redacted]
References
Nuclei Template:
Results
[redacted]