CVE-2018-18419
MEDIUMARDAWAN.COM User Management 1.1 - Stored Cross-Site Scripting via Upload Filename
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-18419. PoCs published by Ismail Tasdelen.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in User Management 1.1 by uploading a malicious .jpg filename via a POST request to the /account URI. The payload triggers an alert when the image fails to load, confirming the vulnerability.
Description
Stored XSS has been discovered in the upload section of ARDAWAN.COM User Management 1.1, as demonstrated by a .jpg filename to the /account URI.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in User Management 1.1 by uploading a malicious .jpg filename via a POST request to the /account URI. The payload triggers an alert when the image fails to load, confirming the vulnerability.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N