CVE-2024-22855
MEDIUMITSS iMLog < 1.308 - Stored Cross-Site Scripting via User Maintenance Last Name Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-22855. PoCs published by Gabriel Felipe.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in iMLog < 1.307 via the 'User Management' feature. An attacker can inject malicious JavaScript into the 'Last Name' field, which executes when an admin views the 'User Maintenance' page.
Description
A cross-site scripting (XSS) vulnerability in the User Maintenance section of ITSS iMLog v1.307 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in iMLog < 1.307 via the 'User Management' feature. An attacker can inject malicious JavaScript into the 'Last Name' field, which executes when an admin views the 'User Maintenance' page.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N