czwartek, 18 lipca 2019

XSS in Zurmo CRM

If you are already familiar with last 2 cases[1, 2] we can run our 'new Burp settings' with 'another webapp'. This time let's try Zurmo CRM. Here we go...

(Thanks to Bitnami) We should start here:

Version I tried:

Quick results:

And we should be somewhere here:

Maybe you'll find it useful.

See you next time.


