TypiCMS/Base

Multiple Stored XSS on version 9.0.30

noobpk opened this issue · 0 comments

Hello. I found some xss vulnerabilities on your version 9.0.30

  1. Stored XSS in Settings on parameter welcome_message and trigger at dashboard

Image Poc:
image
Image XSS trigger:
image

  1. Stored XSS in Pages on parameter Body when using plugin Source Code

Image Poc:
image
Image XSS trigger
image