maschek / imgmap

Javascript based imagemap editor
https://www.maschek.hu/imagemap/
GNU General Public License v2.0
59 stars 33 forks source link

XSS File Upload #86

Open dalpan opened 5 years ago

dalpan commented 5 years ago

Vulnerable URL: http://maschek.hu/imagemap/imgmap/ Vulnerability: File Upload XSS Severity: High Pick any image and name it as “> to make the XSS payload. (Tested on Linux)