Files
CVEs-PoC/2019/CVE-2019-13066.md
T
2025-09-29 21:09:30 +02:00

901 B

CVE-2019-13066

Description

Sahi Pro 8.0.0 has a script manager arena located at s/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updating a script's Script Name, Suite Name, Base URL, Android, iOS, Scripts Run, Origin Machine, or Comment field. The sql parameter can be used to trigger reflected XSS.

POC

Reference

Github