#Exploit Title: PlantUML version 1.2024.6 Cross Site Scripting (XSS) #Date: 23/08/2024 #Exploit Author: Hosein Vita #Vendor Homepage: https://plantuml.com/ #Version: 1.2024.6 #Tested on: Linux Description: This proof-of-concept demonstrates a Cross-Site Scripting (XSS) vulnerability in PlantUML. The vulnerability can be exploited by embedding malicious JavaScript within a diagram using SVG code. When the rendered element is clicked, the payload triggers an alert, demonstrating the potential for executing arbitrary scripts in the user's browser. Proof of Concept: plantuml Copy code @startuml digraph G { graph [bgcolor="white"]; node [shape=box, style="rounded,filled", color="white"]; heading [fillcolor="white", label=<
Error - Failed to load the content. Please click to reload.. |