CVE-2018-11564
CVE-2018-11564
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the system in an SVG format. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the website pointing to "/storage/poc.svg" that will point to http://localhost/pagekit/storage/poc.svg. When a user comes along to click that link, it will trigger a XSS attack.
Affected products
n/a · n/apublic PoCs found — 4
githubgithub.com/GeunSam2/CVE-2018-11564★ 1cve_referencepacketstormsecurity.com/files/148001/PageKit-CMS-1.0.13-Cross-Site-Scripting.htmlunverifiedcve_referencewww.exploit-db.com/exploits/44837/unverifiedexploitdbwww.exploit-db.com/exploits/44837unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →