maccmspro / maccms10

苹果cms-v10,maccms-v10,麦克cms,开源cms,内容管理系统,视频分享程序,分集剧情程序,网址导航程序,文章程序,漫画程序,图片程序
Apache License 2.0
648 stars 127 forks source link

maccms10 super console has a stored XSS vulnerability #27

Open 123lpone opened 6 months ago

123lpone commented 6 months ago

After logging into the backend, click on "Add Article Data." 1710226896060 Add malicious code via hyperlink in the pagination content. image Proceed with saving and storing it on the server. image Exit by clicking on Edit, then click on 123 to trigger XSS. image