vendor:
RSMonials
by:
Unknown
8,8
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: RSMonials
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: Unknown
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Joomla
Unknown
RSMonials XSS Exploit
RSMonials is a Joomla component that allows users to post comments on a website. Anything entered into the form gets rendered as HTML, so malicious scripts can be added as long as they don't include quotes. This component ships with settings that prevent posting by default, but the administrator page for the testimonials renders the script in its entirety. The exploit can be used to remotely upload a file or create a new Super Administrator.
Mitigation:
Ensure that the component is up to date and that all settings are configured correctly.