Skip to content

Cross Site Scripting Vulnerability through the use of Statics Script in FeehiCMS-2.1.1 #72

@githubmof

Description

@githubmof

The steps to reproduce.

Login to the website backend as admin, go to "Setting" - "Website Setting"

In the "Statics Script" code field, write some attack code,just like
<script>alert(1);</script>

image

Success after saving

image

Return to the front-end homepage and discover that the XSS attack has been successful

image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions