The XSS vulnerability will be triggered when you click on the newly created article.
The detailed page of the article will also trigger:
http://192.168.1.132/page/article-info/1233.
The ID created here is 1233, and the actual ID is based on your environment.
Company name: 湖南聚匠信息科技有限公司 Project official website: https://www.dux.cn/. Project address: https://github.com/duxweb/duxcms. Project name: duxcms or dux next. Affected version: v0.3.0-beta
Vulnerability description:
There is a storage XSS vulnerability when creating articles in the background.
准备工作:
insert xss payload
POC:
Go back to the home page:
The XSS vulnerability will be triggered when you click on the newly created article.
The detailed page of the article will also trigger: http://192.168.1.132/page/article-info/1233. The ID created here is 1233, and the actual ID is based on your environment.
Database content: