otale / tale

🦄 Best beautiful java blog, worth a try
https://tale.biezhi.me
MIT License
4.86k stars 1.5k forks source link

Stored XSS vulnerability #605

Open Shydlock opened 1 year ago

Shydlock commented 1 year ago

Stored XSS vulnerability

Process

  1. The XSS vulnerability can be triggered by entering a JavaScript statement starting with "> at the logo of the backend administration

    image-20221228163244635

  2. XSS vulnerability can be triggered by visiting any page

    image-20221228163933449