.. / CVE-2021-30134

Exploit for Php-mod/curl Library <2.3.2 - Cross-Site Scripting (CVE-2021-30134)

Description:

Php-mod/curl library before 2.3.2 contains a cross-site scripting vulnerability via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php. An attacker can inject arbitrary script, which can allow theft of cookie-based authentication credentials and launch of other attacks.

Nuclei Template

View the template here CVE-2021-30134.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-30134.yaml
Copy

References:

https://wpscan.com/vulnerability/0b547728-27d2-402e-ae17-90d539344ec7
https://github.com/ARPSyndicate/kenzer-templates
https://nvd.nist.gov/vuln/detail/CVE-2021-30134