yii-starter-kit / yii2-starter-kit

Yii2 Starter Kit
http://yii2-starter-kit.terentev.net
Other
1.42k stars 648 forks source link

Storage type xss exists in the background #731

Closed wind226 closed 4 years ago

wind226 commented 4 years ago

step1: access:http://backend.yii2-starter-kit.terentev.net/content/page/index Clickimage Fill in:xss payload The last plugin that triggers xss image image

XzAeRo commented 4 years ago

Oof, big yikes.

In general this should be not much of a concern, since modifying pages/article data is behind authentication anyway, but we will have to take a look into this anyway. Not good.

Thanks for the report!