beicheng-maker / vulns

5 stars 0 forks source link

ShowDoc has an XSS vulnerability #6

Open beicheng-maker opened 1 year ago

beicheng-maker commented 1 year ago

github project address : https://github.com/star7th/showdoc Log in to the official sample site https://www.showdoc.com.cn/ example account:2210364486@qq.com example password:huahua123 image The test page has been created, click Edit enter <img src=x onerror=alert(1)> click save image Use Burpsuite to capture packets image Click to release the package access https://www.showdoc.com.cn/2195138658520159/9852226478521844 Click to release the package Crawled the following data packets image So visit https://source.showdoc.com.cn/server/index.php?s=/api/page/info&page_id=9852226478521844&user_token=bb9ced34d72a82a9dfa88563f6ac665ac3e855755324bb622c99ae0f9244b28a&_item_pwd=null image Successful execution of the pop-up window