Thecosy/IceCMS

There is a Stored-XSS vulnerability in IceCMS v1.0.0

Opened this issue · 0 comments

There is a Stored-XSS vulnerability in IceCMS v1.0.0

api : /Websquare/create/circle
planet - circle

POC:
The payload is <img src=1 onerror=alert(1)>

06

05