Posted by Alvaro Diaz on Oct 25
Hello, I found a xss stored vulnerability in Yourls 1.7 script (latest
version).
The attacker can steal the admin’s cookies and login in the admin panel.
Note: Only the admin can see this.
Steps to perform the vulnerability:
1. Create a new url to shorten –> In the inputs you need write this
payload –> anything”><img src=x onerror=prompt(1)>*
* Javascript code to inject.
2. Click in the button “Shorten”…