Panyoujies / bomaos-shop

一款使用Java 语言开发的 个人商城系统
https://free.bomaos.com
GNU General Public License v3.0
223 stars 66 forks source link

Bomaos shop has stored xss vulnerabilitiesBomaos shop has many stored xss vulnerabilities #17

Open Zacarx opened 8 months ago

Zacarx commented 8 months ago

Hi, I want to report some stored xss vulnerability.

  1. “/admin”->"商品管理"->"分类管理"->"添加分类"

image

image

  1. “/admin”->"商品管理"->"添加商品" image

image

  1. “/admin”->"内容管理"->“首页轮播”->"添加轮播图” image image

This means that if hackers obtain editing privileges for these functions (such as providing the account and password of editors), the user's personal information is likely to be attacked