This is a functional proof-of-concept for a stored XSS vulnerability in WSTMart 2.0.8. The exploit demonstrates how an attacker can inject malicious JavaScript via the 'consultContent' parameter in a POST request to the goods consultation feature.
Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:WSTMart 2.0.8_181212
No auth needed
Prerequisites:Access to the target application's goods consultation feature