xsspresso
xsspresso
Tags/ XSS

XSS

3 writeups tagged with XSS

WebMediumLinux

HTB — Cat

Apache mod_rewrite CVE-2024-38472 XSS in redirect. Stored XSS steals admin cookie for Gitea access. SQLite injection and Gitea hook RCE for root.

#XSS#CVE-2024-38472#Gitea
Feb 1, 2025HackTheBox
WebEasyLinux

HTB — Sea

WonderCMS CVE-2023-41425 XSS to RCE via theme upload. Credential reuse for lateral movement. Port-forwarded internal tool for command injection privesc.

#WonderCMS#XSS#RCE
Jan 14, 2025HackTheBox
WebEasyLinux

HTB — Alert

Markdown XSS for stored cross-site scripting. SSRF via file:// to leak local web app source code, exposed internal site with writable path for root.

#XSS#SSRF#Markdown
Jan 10, 2025HackTheBox