CVE-2024-46278
HIGHTeedy 1.11 - Cross-Site Scripting via Management Console
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2024-46278. PoCs published by Ayato Shitomi @ Fore-Z co.ltd, ayato-shitomi.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Teedy 1.11, allowing an attacker to steal cookies and perform account takeover by tricking a victim into downloading a malicious HTML file. The PoC includes a script that sends a POST request to change the victim's password.
Description
Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.
Exploits (2)
This exploit demonstrates a stored XSS vulnerability in Teedy 1.11, allowing an attacker to steal cookies and perform account takeover by tricking a victim into downloading a malicious HTML file. The PoC includes a script that sends a POST request to change the victim's password.
This repository contains a functional proof-of-concept for CVE-2024-46278, demonstrating an XSS vulnerability in Teedy 1.11 that allows account takeover via a crafted HTML file upload. The PoC includes JavaScript code that steals cookies and changes the victim's password upon file download.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H