# Title: phpVirtualBox / CSRF - Stored XSS # Date: 03/04/2018 # Discovered by: @codexlynx # Software Version: <= 5.2 # Category: php, web, csrf, xss [1]CSRF -------------------------------- The backend doesn't validate the origin of the actions. - POC: Shutdown a VM
[2]Stored XSS -------------------------------- Many fields don't sanitize inputs. This vulnerability could allow a user role escalation in the application. - POC: Insert a persistent script in the vm name field. New (Create Virtual Machine) -> Name: Test