-
Notifications
You must be signed in to change notification settings - Fork 28
Open
Description
Vulnerability Product:funboot
Vulnerability version: v1.1
Vulnerability type: Stored XSS
Vulnerability Details:
the Stored XSS payload could let admin causes disclosure of cookies、root path of websites、variables of PHP and stuff
-
First, log in: https://www.funboot.net/backend/site/login
Default account: test
Default password: 123456

-
When creating a message, users, titles, and content can be selected
It is found that the title can construct malicious code storage type XSS to obtain user information and access it through the network

Prove the existence of stored xss
Metadata
Metadata
Assignees
Labels
No labels

