Alumni Management System 1.0 Cross Site Scripting

Alumni Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

MD5 | 19672e38d2fa69e2dc19fb162163b5d8

# Exploit Title: Stored XSS on Alumni Management System 
# Date: 23/10/2020
# Exploit Author: Valerio Alessandroni
# Vendor Homepage:
# Software Link: ource-code.html
# Version: 1.0
# Tested on: ubuntu 18.04
# CVE : CVE-2020-28071
# Description:
An attacker after the admin authentication, can upload an image in the gallery, using a XSS payload in the description textarea called "about" and reach a stored XSS.
# Reproduction:
- Login as "admin"
- upload an image in the gallery area in the administration panel injecting Javascript code in the textarea called "about"
- The obtained XSS affects the administration panel (ex: and
the public gallery (ex:

Related Posts