-
Notifications
You must be signed in to change notification settings - Fork 4
Open
Description
Affected software : flexocms CMS
Version : v.0.1.5
Type of vulnerability : XSS (Cross-Site Scripting)
Author : Noth
Description:
flexocms CMS is susceptible to cross-site scripting attacks, allowing malicious users to inject code into web pages, and other users will be affected when viewing web pages
Step 1 : login system
Step 2 : go to "admin/page/edit/4",There is a storage type XSS in the field (page title).
"><svg/onload=alert(document.cookie)>

Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels
