Authored by tmrswrr

Kopage Website Builder version 4.4.15 suffers from a persistent cross site scripting vulnerability.

#Exploit Title: Kopage Website Builder version 4.4.15 – Stored Cross-Site Scripting (XSS)
#Date: 1/12/2023
#Exploit Author: tmrswrr
#Vendor Homepage:
#Version: Version : 4.4.15
#Tested on:


1 ) Install the system through the website and log in with any user.
2 ) Go to Files field and click upload
3 ) Upload your svg file

Payload :

<svg xmlns="" viewBox="0 0 500 500">

4 ) Open svg file url you will be see alert button.

Url :