# Exploit Title: Auto Dealership & Vehicle Showroom WebSys 1.0 - Persistent Cross-Site Scripting / Cross-Site Request Forgery / Admin panel Authentication bypass # Date: 2018-05-21 # Exploit Author: Borna nematzadeh (L0RD) or borna.nematzadeh123@gmail.com # Vendor Homepage: https://codecanyon.net/item/auto-dealership-vehicle-showroom-websys/17013273?s_rank=28 # Version: 1.0 # Tested on: Kali linux # Description: Auto Dealership & Vehicle Showroom WebSys 1.0 suffers from multiple vulnerabilities: # POC 1 : Persistent cross site scripting : 1) After creating an account , go to your profile. 2) Navigate to "Update profile" and put this payload : "/> 3) You will have an alert box in the page . # POC 2 : CSRF : # Attacker can change user's authentication directly : # User's CSRF exploit :