monstra-cms / monstra

THIS PROJECT IS NOT SUPPORTED ANYMORE! Check FLEXTYPE.ORG
http://flextype.org
MIT License
396 stars 123 forks source link

Cross site scripting in name field of new page #454

Closed dhananjay-bajaj closed 6 years ago

dhananjay-bajaj commented 6 years ago

Vulnerable URL: 'http://localhost/monstra/monstra-dev/admin/index.php?id=pages&action=add_page'

Hello sir, I have found a cross site scripting (XSS) vulnerability in the vulnerable URL. Monstra_3.0.4_XSS.pdf