arterli / CmsWing

一款基于Egg.js(为企业级框架和应用而生)、Sequelize和GraphQL,功能强大的(PC端,手机端和微信公众平台)电子商务平台及CMS建站系统
http://www.cmswing.com
Other
1.35k stars 450 forks source link

Vulnerability Report: CmsWing in version 1.3.7, there are two storage XSS vulnerabilities #54

Open zhooooou opened 4 years ago

zhooooou commented 4 years ago

The first XSS vulnerablity Question and answer module. In the Question supplement function, when inserting a link, fill in "> < SVG / onload = alert ('xss') > <! -- in the address item to form a stored XSS.This vulnerability can be triggered when any visitor views the issue image image

The second XSS vulnerablity Stored XSS exists in the title item of online submission module, and the payload is as follows The specific location of the vulnerability is shown in the figure below,After the submission is approved by the admin user, the vulnerability will be triggered when the administrator opens the content management page. image image