CVE-2021-28420
MEDIUMSeo Panel 4.8.0 - Cross-Site Scripting via alerts.php from_time Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-28420. PoCs published by Piyush Patil.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Seo Panel 4.8.0 via the 'from_time' parameter in alerts.php. The payload injects JavaScript that triggers an alert with the document cookie when the mouse hovers over the 'Period' field.
Description
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time" parameter.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in Seo Panel 4.8.0 via the 'from_time' parameter in alerts.php. The payload injects JavaScript that triggers an alert with the document cookie when the mouse hovers over the 'Period' field.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N