KafDrop - Cross-Site Scripting

By kannthu

Author: dhiyaneshDk Classification CWE-ID: CWE-79 CVSS-Metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N CVSS-Score: 7.2 KafDrop contains a cross-site scripting vulnerability. It allows remote unauthenticated attackers to inject arbitrary HTML and/or JavaScript into the response returned by the server. Reference - - Metadata max-request: 1

Module preview

Concurrent Requests (1)
1. HTTP Request template
Matching conditions
word: Kafdrop, <img src=x onerror=alert(2)>and
status: 500
Passive global matcher
No matching conditions.
On match action
Report vulnerability