{"id":36534,"date":"2023-01-24T10:08:29","date_gmt":"2023-01-24T07:08:29","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/170644\/activeecommercecms650-xss.txt"},"modified":"2023-01-24T11:12:05","modified_gmt":"2023-01-24T07:42:05","slug":"active-ecommerce-cms-6-5-0-cross-site-scripting","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/active-ecommerce-cms-6-5-0-cross-site-scripting\/","title":{"rendered":"Active eCommerce CMS 6.5.0 Cross Site Scripting"},"content":{"rendered":"<p dir=\"ltr\"># Exploit Title: Active eCommerce CMS 6.5.0 &#8211; &#8216;svg&#8217; Stored Cross-Site<br \/>\nScripting (XSS)<br \/>\n# Date: 19\/01\/2023<br \/>\n# Exploit Author: Sajibe Kanti<br \/>\n# Vendor Name: ActiveITzone<br \/>\n# Vendor Homepage: https:\/\/activeitzone.com\/<br \/>\n# Software Link: https:\/\/codecanyon.net\/item\/active-ecommerce-cms\/23471405<br \/>\n# Version: 6.5.0<br \/>\n# Tested on: Live ( Centos &amp; Litespeed Web Server)<br \/>\n# Demo Link : https:\/\/demo.activeitzone.com\/ecommerce\/<\/p>\n<p dir=\"ltr\"># Description #<\/p>\n<p dir=\"ltr\">The Active eCommerce CMS 6.5.0 application has a vulnerability in the<br \/>\nprofile picture upload feature that allows for stored cross-site scripting<br \/>\n(XSS) attacks. Specifically, the vulnerability lies in the handling of<br \/>\n&#8220;svg&#8221; image files, which can contain malicious code. An attacker can<br \/>\nexploit this vulnerability by uploading a specially crafted &#8220;svg&#8221; image<br \/>\nfile as a profile picture, which will then be executed by the application<br \/>\nwhen the user views the profile. This can allow the attacker to steal<br \/>\nsensitive information, such as login credentials, or to perform other<br \/>\nmalicious actions on the user&#8217;s behalf. This vulnerability highlights the<br \/>\nimportance of proper input validation and image file handling in web<br \/>\napplication development.<\/p>\n<p dir=\"ltr\"># Exploit Details #<\/p>\n<p dir=\"ltr\"># Vulnerable Path : \/aiz-uploader\/upload<br \/>\n# Parameter: files (POST)<br \/>\n# Vector: &lt;svg version=&#8221;1.1&#8243; baseProfile=&#8221;full&#8221; xmlns=&#8221;<br \/>\nhttp:\/\/www.w3.org\/2000\/svg&#8221;&gt;<br \/>\n&lt;rect width=&#8221;300&#8243; height=&#8221;100&#8243;<br \/>\nstyle=&#8221;fill:rgb(0,0,255);stroke-width:3;stroke:rgb(0,0,0)&#8221; \/&gt;<br \/>\n&lt;script type=&#8221;text\/javascript&#8221;&gt;<br \/>\nalert(&#8220;haha XSS&#8221;);<br \/>\n&lt;\/script&gt;<br \/>\n&lt;\/svg&gt;<\/p>\n<p dir=\"ltr\"># Proof of Concept (PoC) : Exploit #<\/p>\n<p dir=\"ltr\">1) Goto: https:\/\/localhost<br \/>\n2) Click Registration<br \/>\n3) Login Your Account<br \/>\n4) Go Manage Profile<br \/>\n5) Now Upload Given Vector as anyname.svg (you must put vector code in<br \/>\nanyname.svg file)<br \/>\n6) After Upload Clic to view Your profile picture<br \/>\n7) XSS Popup Will Fired<\/p>\n<p dir=\"ltr\"># Image PoC : Reference Image #<\/p>\n<p dir=\"ltr\">1) Payload Fired: https:\/\/prnt.sc\/cW0F_BtpyMcv<\/p>\n","protected":false},"excerpt":{"rendered":"<p># Exploit Title: Active eCommerce CMS 6.5.0 &#8211; &#8216;svg&#8217; Stored Cross-Site Scripting (XSS) # Date: 19\/01\/2023 # Exploit Author: Sajibe Kanti # Vendor Name: ActiveITzone # Vendor Homepage: https:\/\/activeitzone.com\/ # Software Link: https:\/\/codecanyon.net\/item\/active-ecommerce-cms\/23471405 # Version: 6.5.0 # Tested on: Live ( Centos &amp; Litespeed Web Server) # Demo Link : https:\/\/demo.activeitzone.com\/ecommerce\/ # Description # The &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-36534","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/36534","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=36534"}],"version-history":[{"count":2,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/36534\/revisions"}],"predecessor-version":[{"id":36551,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/36534\/revisions\/36551"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=36534"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=36534"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=36534"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}