Hey what's up?
Website : ghostkernel.org
Vulnerability : Stored XSS
Discovered and Explored by @uromulou
1 . Go to website.
2 . Get in some news commentary.
3 . Click In "Write a Comment...".
4 . In the name put your JS code, my is: <script>alert('@uromulou: Reporting Stored XSS');</script> .
5 . In the email, if you're smart, you probably didn't put your real address.
6 . In the comment put anything, the real problem is in the name.
7 . Solve captcha, it's annoying.
And ready! you just put your code on the site.
Some examples : https://ghostkernel.org/news/shared-library-support-added-61#comments
https://ghostkernel.org/news/started-redux-58#comments
https://ghostkernel.org/news/documentation-available-59#comments