havok89 / Hoosk

Hoosk Codeigniter CMS
http://hoosk.org
Other
128 stars 87 forks source link

XSS on Hoosk v1.7.0 #47

Closed Hu3sky closed 4 years ago

Hu3sky commented 6 years ago

the xss is on the page 'admin/pages/new',add a text new page, fill the <img src=1 onerror=alert(1)> in the 'Navigation Title* (this is displayed on navigation menus)' field tim 20180819142717 tim 20180819142913

havok89 commented 6 years ago

I was sure all the inputs were sanitising data but appears not. I suppose at this point an attacker would already have access to your admin dashboard so the site would already be compromised.

I'll try get time to fix it in the next few days!