Taiwan-Tech-WebSec / Bug-Report

4 stars 0 forks source link

B10815054之漏洞回報 #44

Open Pei-ChiTsai opened 2 years ago

Pei-ChiTsai commented 2 years ago

攻擊者學號:B10704134 @Pei-ChiTsai 被攻擊者學號與網址:B10815054 @Danielh9016 https://demo.b10815054.works/

漏洞類型:XSS(title)

漏洞描述

根據之前的漏洞回報 得知 管理員帳密 帳號: you 密碼: pass 進入更改標題後輸入 會彈跳視窗

PoC:

<script>alert("hello")</script>

圖: image image image