Exploit Title: Perch v3.2 - Stored XSS Application: Perch Cms Version: v3.2 Bugs: XSS Technology: PHP Vendor URL: https://grabaperch.com/ Software Link: https://grabaperch.com/download Date of found: 21.07.2023 Author: Mirabbas Ağalarov Tested on: Linux 2. Technical Details & POC ======================================== steps: 1. login to account 2. go to http://localhost/perch_v3.2/perch/core/settings/ 3. upload svg file """ """ 4. go to svg file (http://localhost/perch_v3.2/perch/resources/malas.svg)