millken / doyocms

DOYO通用建站程序,PHP免费开源企业CMS建站系统,官方网站:http://wdoyo.com
4 stars 5 forks source link

Stored-XSS Vulnerabilities(Administrator Privilege) #2

Open Attrck opened 5 years ago

Attrck commented 5 years ago

Holes for details: 1、Login the backstage: http://192.168.53.130:81/doyocms/admin.php 2、The article management—The editor image 3、The input:"> image

image

fgeek commented 5 years ago

Please use https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9551 for this vulnerability.