ualink / phpb2b

PHPB2B is an opensource and free b2b program.
http://www.phpb2b.com
GNU General Public License v3.0
27 stars 16 forks source link

Xss vulnerability exists in action parameter #6

Open script-alert1-script opened 3 years ago

script-alert1-script commented 3 years ago

Steps to reproduce the behavior url:http://localhost/phpb2b/ajax.php?action=

The page automatically loads and triggers XSS image

poc:

Restoration suggestions: Filter all input

ualink commented 3 years ago

Thank you for your useful suggestions, and you can download the latest version to repair the problem.