Posted by Andrey Stoykov on Jun 03
# Exploit Title: Stored XSS via File Upload – adaptcmsv3.0.3
# Date: 06/2025
# Exploit Author: Andrey Stoykov
# Version: 3.0.3
# Tested on: Debian 12
# Blog: https://msecureltd.blogspot.com/
Stored XSS via File Upload #1:
Steps to Reproduce:
1. Login with low privilege user and visit “Profile” > “Edit Your Profile”
2. Click on “Choose File” and upload the following file
html-xss.html
<!DOCTYPE html>…
– Read More – Full Disclosure