CVE-2021-28418
MEDIUMSeo Panel 4.8.0 - Cross-Site Scripting via Category Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-28418. PoCs published by Piyush Patil.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Seo Panel 4.8.0 via the 'category' parameter. The payload injects JavaScript that triggers an alert with the document cookie when the mouse hovers over the 'Cancel' field.
Description
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category" parameter.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in Seo Panel 4.8.0 via the 'category' parameter. The payload injects JavaScript that triggers an alert with the document cookie when the mouse hovers over the 'Cancel' field.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N