MineWeb / MineWebCMS

🚀 A French Minecraft CMS since 2015 (used by +1k websites)
https://mineweb.org
GNU General Public License v3.0
92 stars 41 forks source link

There is a Stored XSS in MineWebCMS 1.70. #154

Closed Lilc1 closed 5 years ago

Lilc1 commented 5 years ago

Adding code options in the Preferences other page via /MineWebCMS/admin/configuration results in Stored XSS.

image image image image

The image only shows the acquisition of cookies, this vulnerability can also be used for intranet detection, keyloggers and other operations.

Eywek commented 5 years ago

duplicate https://github.com/MineWeb/MineWebCMS/issues/123