XenForo Releases

Xenforo Vulnerability [PERSISTENT XSS] [0DAY]

Submitted by Deadboy, , Thread ID: 32662

Thread Closed
Deadboy
Active Member
Level:
0
Reputation:
18
Posts:
219
Likes:
23
Credits:
148
17-04-2017, 10:23 PM
#1
There is a stored XSS Vulnerability affecting the alert system for XenForo CMS. It allows an authenticated attacker
to create specialized payloads that are highly flexible in terms of who they want to target. It also allows an
attacker to replace the contents of the index page despite this not being possible via regular admin access. Payloads
can be 'timed', meaning that an attackers code can execute even AFTER they've lost access to their account with privs.


Content locked
This content has been locked. Please login or register in order to unlock it.

RE: Xenforo Vulnerability [PERSISTENT XSS] [0DAY]

Trust3dTeam
Newbie
Level:
0
Reputation:
0
Posts:
15
Likes:
0
Credits:
1
07-05-2017, 11:31 AM
#2
this is real i really wanted to exploit websites

RE: Xenforo Vulnerability [PERSISTENT XSS] [0DAY]

abukk1000
Newbie
Level:
0
Reputation:
0
Posts:
10
Likes:
1
Credits:
11
12-05-2017, 10:06 PM
#3
Hmm, I will see what I will be able to do. Thanks for fun man :D

RE: Xenforo Vulnerability [PERSISTENT XSS] [0DAY]

suckling
Newbie
Level:
0
Reputation:
0
Posts:
15
Likes:
0
Credits:
19
20-05-2017, 01:11 AM
#4
Absolutely recommended add-on with a lot of helpful features, works perfectly for me. I received incredible support from the author, thank you very much for this. Keep up the great work, au lait! Smile

RE: Xenforo Vulnerability [PERSISTENT XSS] [0DAY]

sfn
Newbie
Level:
0
Reputation:
0
Posts:
17
Likes:
0
Credits:
1
29-05-2017, 03:55 AM
#5
Has this been fixed?

RE: Xenforo Vulnerability [PERSISTENT XSS] [0DAY]

Guest
Level:
0
Posts:
N/A
Likes:
0
Credits:
0
03-07-2017, 07:31 PM
#6
You're the best. thanks for leaking this source

RE: Xenforo Vulnerability [PERSISTENT XSS] [0DAY]

Zenprogamer
Lurker
Level:
0
Reputation:
0
Posts:
1
Likes:
0
Credits:
1
20-07-2017, 02:30 AM
#7
nice i will look forward to it

RE: Xenforo Vulnerability [PERSISTENT XSS] [0DAY]

King2828
Newbie
Level:
0
Reputation:
0
Posts:
15
Likes:
0
Credits:
0
07-08-2017, 10:46 PM
#8
really need this thanks

RE: Xenforo Vulnerability [PERSISTENT XSS] [0DAY]

DaNnIbOi
unD SlS ll y
Level:
1
Reputation:
17
Posts:
148
Likes:
45
Credits:
317
08-08-2017, 07:58 PM
#9
The first line reads "This is a low impact bug due to the fact that a mod/admin account is required on the forums in order to trigger the vulnerability" so it's not worth it!
Cool People:
Aoki, Aurora, fdigl, Faded, v4hl, EMO

Users browsing this thread: 1 Guest(s)