maccmspro / maccms10

苹果cms-v10,maccms-v10,麦克cms,开源cms,内容管理系统,视频分享程序,分集剧情程序,网址导航程序,文章程序,漫画程序,图片程序
Apache License 2.0
648 stars 127 forks source link

xss attacks on background #23

Closed Cedric1314 closed 1 year ago

Cedric1314 commented 1 year ago

Go to background, go to Basics > AD Management > Name,

Insert payload1 in the name box:

It can cause XSS attacks. Vulnerability name:Storage type xss Vulnerability level:Medium risk Vulnerability location: http://127.0.0.1/admin.php/admin/banner/infocat.html mac6 mac7

joyce2022 commented 1 year ago

Fixed