Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
- Feehi CMS 2.1.1 Cross Site Scripting[6]
- Authored by Shivam Singh[7]
-
Feehi CMS version 2.1.1 suffers from a persistent cross site scripting vulnerability.
- advisories | CVE-2022-34140[8]
- SHA-256 |
d361efcdb1b82d5a2eb48510dede7b1357037345197851159d3a6375b4284b66 - Download[9] | Favorite[10] | View[11]
Change Mirror[12] Download[13]
# Exploit Title: Feehi CMS 2.1.1 - Stored Cross-Site Scripting (XSS)
# Date: 02-08-2022
# Exploit Author: Shivam Singh
# Vendor Homepage: https://feehi.com/
# Software Link: https://github.com/liufee/cms
#Profile Link: https://www.linkedin.com/in/shivam-singh-3906b0203/
# Version: 2.1.1 (REQUIRED)
# Tested on: Linux, Windows, Docker
# CVE : CVE-2022-34140
# Proof of Concept:
1-Sing-up https://localhost.cms.feehi/
2-Inject The XSS Payload in Username:
"><script>alert(document.cookie)</script> fill all required fields and
click the SignUp button
3-Login to Your Account, Go to any article page then XSS will trigger.
File Tags
- ActiveX[18] (932)
- Advisory[19] (77,926)
- Arbitrary[20] (15,184)
- BBS[21] (2,859)
- Bypass[22] (1,576)
- CGI[23] (1,013)
- Code Execution[24] (6,715)
- Conference[25] (671)
- Cracker[26] (797)
- CSRF[27] (3,274)
- DoS[28] (21,926)
- Encryption[29] (2,335)
- Exploit[30] (49,987)
- File Inclusion[31] (4,152)
- File Upload[32] (945)
- Firewall[33] (821)
- Info Disclosure[34] (2,559)
- Intrusion Detection[35] (858)
- Java[36] (2,821)
- JavaScript[37] (801)
- Kernel[38] (6,089)
- Local[39] (14,036)
- Magazine[40] (586)
- Overflow[41] (12,233)
- Perl[42] (1,413)
- PHP[43] (5,054)
- Proof of Concept[44] (2,283)
- Protocol[45] (3,328)
- Python[46] (1,404)
- Remote[47] (29,782)
- Root[48] (3,453)
- Ruby[49] (578)
- Scanner[50] (1,630)
- Security Tool[51] (7,715)
- Shell[52] (3,066)
- Shellcode[53] (1,203)
- Sniffer[54] (882)
- Spoof[55] (2,103)
- SQL Injection[56] (16,039)
- TCP[57] (2,364)
- Trojan[58] (676)
- UDP[59] (868)
- Virus[60] (660)
- Vulnerability[61] (30,539)
- Web[62] (9,071)
- Whitepaper[63] (3,720)
- x86[64] (943)
- XSS[65] (17,359)
- Other[66]
File Archives
- August 2022[67]
- July 2022[68]
- June 2022[69]
- May 2022[70]
- April 2022[71]
- March 2022[72]
- February 2022[73]
- January 2022[74]
- December 2021[75]
- November 2021[76]
- October 2021[77]
- September 2021[78]
- Older[79]
Systems
- AIX[80] (426)
- Apple[81] (1,890)
- BSD[82] (368)
- CentOS[83] (55)
- Cisco[84] (1,913)
- Debian[85] (5,948)
- Fedora[86] (1,690)
- FreeBSD[87] (1,241)
- Gentoo[88] (4,158)
- HPUX[89] (878)
- iOS[90] (319)
- iPhone[91] (108)
- IRIX[92] (220)
- Juniper[93] (67)
- Linux[94] (42,582)
- Mac OS X[95] (683)
- Mandriva[96] (3,105)
- NetBSD[97] (255)
- OpenBSD[98] (478)
- RedHat[99] (11,825)
- Slackware[100] (941)
- Solaris[101] (1,607)
- SUSE[102] (1,444)
- Ubuntu[103] (7,926)
- UNIX[104] (9,098)
- UnixWare[105] (185)
- Windows[106] (6,442)
- Other[107]


