Taiwan-Tech-WebSec / Bug-Report

4 stars 0 forks source link

B10815041之漏洞回報 #87

Closed LegalCheng closed 2 years ago

LegalCheng commented 2 years ago

攻擊者學號:B10809023 @LegalCheng

被攻擊者學號與網址:B10815041 @Shing227 https://demo.shing227.works/

漏洞類型:XSS (color tag)

漏洞描述: 留言欄位注入[color=red]a<!--[/color]後再也沒人可以留言了

Poc: [color=red]a</span><!--[/color]

螢幕擷取畫面 2022-05-02 034453

splitline commented 2 years ago

dup with #75 而且你沒有跑 js