Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-43271 PoC — Inhabit Systems Move CRM 跨站脚本漏洞

Source
Associated Vulnerability
Title:Inhabit Systems Move CRM 跨站脚本漏洞 (CVE-2022-43271)
Description:Inhabit Systems Pty Ltd Move CRM version 4, build 260 was discovered to contain a cross-site scripting (XSS) vulnerability via the User profile component.
Readme
# CVE-2022-43271

## Stored Cross-Site Scripting (XSS) 

Product: Move CRM (https://inhabit.com.au/Move-Real-Estate-CRM-Software)

Discovery date: 2/8/2022

Fix date: 4/8/2022

Affected Version: version 4, build 260

Fixed Version: version 4, build 261

Description:
The vulnerability was discovered in the 'staff settings' of the CRM, specifically in the 'Profile' text box. When saving the changes and intercepting the POST request, the 'lProfileCopy' parameter can be modified to include an XSS payload and bypass front-end filtering.
File Snapshot

[4.0K] /data/pocs/0d2a1b2310a1b585c589a0554ddfaf7af396c7ef └── [ 538] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →