.. / CVE-2022-31299

Exploit for Haraj 3.7 - Cross-Site Scripting (CVE-2022-31299)

Description:

Haraj 3.7 contains a cross-site scripting vulnerability in the User Upgrade Form. An attacker can inject malicious script and thus steal authentication credentials and launch other attacks.

Nuclei Template

View the template here CVE-2022-31299.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-31299.yaml
Copy

References:

https://github.com/bigzooooz/CVE-2022-31299
https://angtech.org/product/view/3
https://angtech.org
https://nvd.nist.gov/vuln/detail/CVE-2022-31299
https://github.com/trhacknon/Pocingit