Skip to content

Cross-Site Scripting v0.1.5 #26

@zxc7528064

Description

@zxc7528064

Affected software : flexocms CMS

Version : v.0.1.5

Type of vulnerability : XSS (Cross-Site Scripting)

Author : Noth

Description:
flexocms CMS is susceptible to cross-site scripting attacks, allowing malicious users to inject code into web pages, and other users will be affected when viewing web pages

Step 1 : login system

Step 2 : go to "admin/page/edit/4",There is a storage type XSS in the field (page title).
"><svg/onload=alert(document.cookie)>
1

Step 3 : Back to the front desk ,Click "Contacts"
3

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions