philippe / FrogCMS

Frog CMS simplifies content management by offering an elegant user interface, flexible templating per page, simple user management and permissions, as well as the tools necessary for file management.
GNU General Public License v3.0
160 stars 36 forks source link

Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability #7

Open Oran9e opened 6 years ago

Oran9e commented 6 years ago

I have found a stored Cross Site Scripting Vulnerability. log into the system as an administrator role:http://127.0.0.1/test/FrogCMS-master/admin/ publish an article,and you can click it. snippet-->Edit snippet-->Name payload:"/>"/>