havok89 / Hoosk

Hoosk Codeigniter CMS
http://hoosk.org
Other
128 stars 87 forks source link

XSS on Hoosk v1.8 #63

Open nhienit2010 opened 2 years ago

nhienit2010 commented 2 years ago

This vulnerability in edit page function

image

Exploit with using "heading" attribute, we can custom HTML tag lead to inject img tag with onerror event, and use HTML encoding to bypass filter some special chars

image

PoC image