.. / CVE-2023-30212

Exploit for OURPHP <= 7.2.0 - Cross Site Scripting (CVE-2023-30212)

Description:

OURPHP <= 7.2.0 is vulnerale to Cross Site Scripting (XSS) via /client/manage/ourphp_out.php.

Nuclei Template

View the template here CVE-2023-30212.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2023/CVE-2023-30212.yaml
Copy

References:

https://github.com/arunsnap/CVE-2023-30212-POC
https://github.com/JasaluRah/Creating-a-Vulnerable-Docker-Environment-CVE-2023-30212-
https://nvd.nist.gov/vuln/detail/CVE-2023-30212
https://www.ourphp.net/
https://wanheiqiyihu.top/2023/03/27/OURPHP-v7-2-0-ourphp-out-php-Reflection-xss/