Skip to content
This repository was archived by the owner on Jan 10, 2019. It is now read-only.

Stored-XSS Vulnerability Found in System setting -> site setting-> POSTdata:site_domain #62

@fakerrr

Description

@fakerrr

1、Login the backstage
http://127.0.0.1/admin/index.php

2、Go to System setting->site setting
image

3、add the following payload to the second textbox,and submit。
payload:site_domain=http://www.dilicms.com/" onmouseover="alert(1)
image
And move your mouse on the second textbook ,then Stored-XSS triggered

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions