Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-13427. PoCs published by Nitya Nand.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in Victor CMS 1.0 by injecting malicious scripts into the 'user_name', 'user_firstname', and 'user_lastname' parameters via a POST request. The payload is embedded in a multipart/form-data request, which is then stored and executed when the user data is rendered.
Description
Victor CMS 1.0 has Persistent XSS in admin/users.php?source=add_user via the user_name, user_firstname, or user_lastname parameter.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in Victor CMS 1.0 by injecting malicious scripts into the 'user_name', 'user_firstname', and 'user_lastname' parameters via a POST request. The payload is embedded in a multipart/form-data request, which is then stored and executed when the user data is rendered.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N