[-] Title : Nextpost 4.1 - Cross-Site Scripting
[-] Author : Ashkan Moghaddas
[-] Vendor : https://getnextpost.io
[-] Category : Webapps
[-] Date : 07.2.2018
[-] Google Dork: N/A
Vulnerable page :
app/lib/OneFileManager/Common.php
Vulnerable Source :
Line52: echo echo json_encode($output) : $_GET['callback'] . "(" . json_encode($output) . ")";
POC :
http://localhost/app/lib/OneFileManager/Common.php?callback=[XSS]
================================
WebSite : UltraSec.Org
Channel : @UltraSecurity
Email : ashkanmoghaddas77@gmail.com
Special Thanks : abolfazl hajizade , MrQadir , Milad Ranjbar