Thecosy / IceCMS

🌈冰激凌内容管理系统🍦,实现MacWK资源站,社区图片视频圈子CMS,支持网页端移动端小程序🌟适合做 资讯商城,社区论坛,聊天交友 社区,博客,圈子,论坛,图片,视频,社交。
https://www.icecms.cn
GNU Affero General Public License v3.0
1.62k stars 237 forks source link

There is a Stored-XSS vulnerability in IceCMS v1.0.0 #8

Open topdayplus opened 1 year ago

topdayplus commented 1 year ago

There is a Stored-XSS vulnerability in IceCMS v1.0.0

api : /Websquare/create/circle planet - circle

POC: The payload is <img src=1 onerror=alert(1)>

06

05