GigToDo 1.3 - Cross-Site Scripting 漏洞概述 EDB-ID: 47185 CVE: N/A Author: M0ZE Type: WEBAPPS Platform: PHP Date: 2019-07-29 Vulnerable App: GigToDo - Freelance Marketplace Script v1.3 Persistent XSS Injection 影响范围 Vendor Homepage: https://www.gigtodoproject.com Software Link: https://codecanyon.net/item/gigtodofreelance-marketplace-script/23855397 Version: 1.3 Tested on: NginX/1.15.10 CVE: N/A CWE: CWE-79 修复方案 Details & Description: - 该漏洞允许攻击者通过反射和持久性XSS注入,将JavaScript/HTML代码注入前端,重定向访问者到另一个网站或窃取管理员cookie。 POC代码 `` M0ZE Script is fully protected from SQL Injection and XSS © For sure lol Greetz from M0ZE https://twitter.com/M0ZE_ru`);'>