{"id":26535,"date":"2022-07-04T19:28:34","date_gmt":"2022-07-04T15:28:34","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/167687\/paymoney33-xss.txt"},"modified":"2022-07-12T08:42:51","modified_gmt":"2022-07-12T04:12:51","slug":"paymoney-3-3-cross-site-scripting","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/paymoney-3-3-cross-site-scripting\/","title":{"rendered":"Paymoney 3.3 Cross Site Scripting"},"content":{"rendered":"<dl id=\"F167687\" class=\"file first\">\n<dt dir=\"ltr\"><a class=\"ico text-plain\" title=\"Size: 0.7 KB\" href=\"https:\/\/packetstormsecurity.com\/files\/download\/167687\/paymoney33-xss.txt\" target=\"_blank\" rel=\"noopener\"><strong>Paymoney 3.3 Cross Site Scripting<\/strong><\/a><\/dt>\n<dd class=\"datetime\" dir=\"ltr\">Posted <a title=\"14:22:00 UTC\" href=\"https:\/\/packetstormsecurity.com\/files\/date\/2022-07-04\/\" target=\"_blank\" rel=\"noopener\">Jul 4, 2022<\/a><\/dd>\n<dd class=\"refer\" dir=\"ltr\">Authored by <a class=\"person\" href=\"https:\/\/packetstormsecurity.com\/files\/author\/14758\/\" target=\"_blank\" rel=\"noopener\">nu11secur1ty<\/a><\/dd>\n<dd class=\"detail\" dir=\"ltr\">Paymoney version 3.3 suffers from a cross site scripting vulnerability.<\/dd>\n<dd class=\"tags\" dir=\"ltr\">tags | <a href=\"https:\/\/packetstormsecurity.com\/files\/tags\/exploit\" target=\"_blank\" rel=\"noopener\">exploit<\/a>, <a href=\"https:\/\/packetstormsecurity.com\/files\/tags\/xss\" target=\"_blank\" rel=\"noopener\">xss<\/a><\/dd>\n<dd class=\"md5\" dir=\"ltr\">SHA-256 | <code>5cc7c6a3d00e691e2a81d9cf0db8ad5e6b88fc993d898fd9d54b3c0511bcc5e3<\/code><\/dd>\n<dd class=\"act-links\" dir=\"ltr\"><a title=\"Size: 0.7 KB\" href=\"https:\/\/packetstormsecurity.com\/files\/download\/167687\/paymoney33-xss.txt\" rel=\"nofollow noopener\" target=\"_blank\">Download<\/a> | <a class=\"fav\" href=\"https:\/\/packetstormsecurity.com\/files\/favorite\/167687\/\" rel=\"nofollow noopener\" target=\"_blank\">Favorite<\/a> | <a href=\"https:\/\/packetstormsecurity.com\/files\/167687\/Paymoney-3.3-Cross-Site-Scripting.html\" target=\"_blank\" rel=\"noopener\">View<\/a><\/dd>\n<\/dl>\n<div class=\"src\" dir=\"ltr\">\n<pre><code>## Title: paymoney-3.3 XSS-Reflected\r\n## Author: nu11secur1ty\r\n## Date: 07.02.2022\r\n## Vendor: https:\/\/paymoney.techvill.org\/\r\n## Software: paymoney-3.3\r\n## Reference: https:\/\/github.com\/nu11secur1ty\/CVE-nu11secur1ty\/tree\/main\/vendors\/paymoney\/2022\/paymoney-3.3<\/code><\/pre>\n<p>Description:<br \/>\nThe parameters first_name and last_name in Users are vulnerable from<br \/>\nXSS-Reflected on Paymoney-3.3. The already authenticated users can be<br \/>\nhijacking the XSRF-Token and they can use it for malicious purposes on<br \/>\ninternal and external domains.<\/p>\n<pre><code><\/code><\/pre>\n<p>STATUS: Medium<\/p>\n<pre><code><\/code><\/pre>\n<p>## Reproduce:<br \/>\n[href](https:\/\/github.com\/nu11secur1ty\/CVE-nu11secur1ty\/tree\/main\/vendors\/paymoney\/2022\/paymoney-3.3)<\/p>\n<pre><code><\/code><\/pre>\n<p>## Proof and Exploit:<br \/>\n[href](https:\/\/streamable.com\/fhzvyr)<\/p>\n<pre><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre><code><\/code><\/pre>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Paymoney 3.3 Cross Site Scripting Posted Jul 4, 2022 Authored by nu11secur1ty Paymoney version 3.3 suffers from a cross site scripting vulnerability. tags | exploit, xss SHA-256 | 5cc7c6a3d00e691e2a81d9cf0db8ad5e6b88fc993d898fd9d54b3c0511bcc5e3 Download | Favorite | View ## Title: paymoney-3.3 XSS-Reflected ## Author: nu11secur1ty ## Date: 07.02.2022 ## Vendor: https:\/\/paymoney.techvill.org\/ ## Software: paymoney-3.3 ## Reference: https:\/\/github.com\/nu11secur1ty\/CVE-nu11secur1ty\/tree\/main\/vendors\/paymoney\/2022\/paymoney-3.3 Description: The &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-26535","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/26535","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=26535"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/26535\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=26535"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=26535"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=26535"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}