NewsLister suffers from a persistent cross site scripting vulnerability.

# Exploit Title: NewsLister - Authenticated Persistent Cross-Site Scripting
# Date: 2020-11-27
# Exploit Author: Emre Aslan
# Vendor Homepage:
# Tested on: Windows & XAMPP

==> PoC <==

1- Login to admin panel.
2- Enter the payload to title value.
3- View the news. XSS will be execute.

==> HTTP Request <==

GET /admin/index.php?page=add HTTP/1.1
Referer: host/admin/index.php?page=home
