flatCore/flatCore-CMS

XSS

Closed this issue · 0 comments

Describe the bug
XSS in function Posts

To Reproduce
Steps to reproduce the behavior:

  1. Login to CMS
  2. Click on 'Posts' >> 'New Entry' >> Image
  3. In Meta Data >> inject payload into Title
    Screenshots
    image

payload: "><img src="x" onerror=alert(String.fromCharCode(88,83,83));>

Desktop (please complete the following information):

  • OS: All
  • Browser : All
  • Version: Last versiom