Mcculloughj / codeql-javascript-unsafe-jquery-plugin

https://lab.github.com/githubtraining/codeql-for-javascript:-unsafe-jquery-plugin
2 stars 1 forks source link

When common user send this malicious URL to the web manager and request it, the web manager could be executed the malicious javascript code #4

Open Mcculloughj opened 3 years ago

Mcculloughj commented 3 years ago

When common user send this malicious URL to the web manager and request it, the web manager could be executed the malicious javascript code

XSRF.Vulnerability.exists.in.the.file.of.DedeCMS.V5.7sp2.pdf

Originally posted by @TaroballzChen in https://github.com/ky-j/dedecms/issues/12