slims / slims7_cendana

SLiMS 7 Cendana official source code repository
28 stars 49 forks source link

Cross-site Scripting (XSS) #51

Open honcbb opened 7 years ago

honcbb commented 7 years ago

Hi, I'm in your 7 version open source found to detail_template.php this page parameter value ID does not filter in the output or filter or escape the input character to cause XSS

Affected Files:

/template/default-rtl/detail_template.php

Poc Payload:

http://site/template/default-rtl/detail_template.php?id=%22%3E%3Csvg/onload=alert(domain)%3E%22

Resolving: Filtering encoding or escaping

default 1