[-] Title : Raspina CMS - 2.3.5 - Cross-Site-Scripting
[-] Author : Abolfazl Feyz
[-] Vendor : http://dl.persianscript.ir/script/raspina%5B2.3.5%5D%28PersianScript.ir%29.zip
[-] date : 8.January.2021
------------------------------------
Vulnerable page:
/vendor/ezyang/htmlpurifier/maintenance/flush-definition-cache.php
------------------------------------
---------------------------------------------------
Vulnerable source:
Line28 : $names = $argv[1] // array() if(isset($argv)), if(in_array($argv, $names))
Line34 : foreach($names as $name)
Line35 : echo echo " - Flushing $name\n";
----------------------------------------------------
--------------------------------------------------------
POC :
http://site.com/Raspina/vendor/ezyang/htmlpurifier/maintenance/flush-definition-cache.php?argv=[XSS]
--------------------------------------------------------
==========================
= cantact me =
= Telegram ==> @Mr_ramkal =
= instagram ==> aboolfazl.feyz =
= email ==> khodebolfazl@gmail.com =
==========================