chekun / DiliCMS

DiligentCMS
http://www.dilicms.com/
MIT License
190 stars 101 forks source link

Stored-XSS Vulnerability Found in System setting -> site setting-> POSTdata:site_logo #63

Open fakerrr opened 5 years ago

fakerrr commented 5 years ago

1、Login the backstage http://127.0.0.1/admin/index.php

2、Go to System setting->site setting image

3、add the following payload to the third textbox,and submit。 payload:site_logo=images/logo.gif" onmouseover="alert(1) image And move your mouse on the third textbook ,then Stored-XSS triggered