header-logo
Suggest Exploit
vendor:
EgavilanMedia User Registration & Login System with Admin Panel
by:
Mesut Cetin
8.8
CVSS
HIGH
Stored Cross-Site Scripting
79
CWE
Product Name: EgavilanMedia User Registration & Login System with Admin Panel
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:egavilanmedia:egavilanmedia_user_registration_and_login_system_with_admin_panel
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: Windows 10, Firefox 83.0, Burp Suite Professional v1.7.34
2020

EgavilanMedia User Registration & Login System with Admin Panel 1.0 – Multiple Stored Cross-Site Scripting

To bypass client-side filter, an attacker can use Burp Suite to manipulate the parameter in the POST request and inject a malicious payload. This will allow the attacker to steal the session cookie and hijack the user's session.

Mitigation:

Implement input validation and output encoding to prevent malicious payloads from being injected.
Source

Exploit-DB raw data: