instantsoft / icms2

Self-hosted Site Management System
https://instantcms.ru
GNU General Public License v2.0
295 stars 120 forks source link

XSS store in nickname paramerter when install #1405

Closed Nguyen-Trung-Kien closed 2 years ago

Nguyen-Trung-Kien commented 2 years ago

Hi team, when i install i will check xss in it and it so bad when i found xss store in this look that image

and result

image

it's so bad, please fix it

fuzegit commented 2 years ago

We'll fix it of course, but who in their right mind would do that when installing their own site?

Nguyen-Trung-Kien commented 2 years ago

I thinks it bug in your project, and i don't know who inject xss payload :))

fuzegit commented 2 years ago

We'll fix it, thank you. But it's in the CMS installer, you understand that it's unrealistic to use this XSS.