BlackCatDevelopment / BlackCatCMS

BlackCat CMS is a PHP5, HTML5 content management system
https://blackcat-cms.org
Other
11 stars 9 forks source link

XSS in Blackcat cms v1.2 #373

Closed faizzaidi closed 7 years ago

faizzaidi commented 7 years ago

Hello,

I would like to report a vulnerability that I have found on Blackcat cms v1.2 in which Cross Site Scripting(XSS) attack is possible.

For details please go through attached document.

Blackcat cms v1.2 xss POC by Provensec llc.pdf

Regards, Faiz Ahmed Zaidi

webbird commented 7 years ago

Deleted the PDF to protect our users.

Thank you for testing and reporting this issue. We will fix it as soon as possible.

faizzaidi commented 7 years ago

Hello, Did you guys patch that vulnerability?

webbird commented 7 years ago

Sure, see the commit. :)