Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-28623. PoCs published by Gurjot Singh. A Nuclei detection template is also available.
AI-analyzed exploit summary This is a reflected XSS exploit for RiteCMS 3.0.0, leveraging the `main_menu/edit_section` parameter to execute arbitrary JavaScript in the victim's browser session. The PoC includes a payload and steps to reproduce the vulnerability.
Description
RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.
Exploits (1)
This is a reflected XSS exploit for RiteCMS 3.0.0, leveraging the `main_menu/edit_section` parameter to execute arbitrary JavaScript in the victim's browser session. The PoC includes a payload and steps to reproduce the vulnerability.
Nuclei Templates (1)
title="RiteCMS"
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N