sanluan/PublicCMS

There is an XSS vulnerability in managing background file management

CyberIKUN opened this issue · 1 comments

Storage XSS
On this page as shown in the figure,
image
click 创建文件
image
As shown in the figure below, creat xx.html file, enter <script>alert(1)</script>,click 保存
image

Then click 查看

image

Trigger vulnerability

image

这是一个在线编辑html的基础功能 不是安全漏洞 任何干扰编辑html的措施都将使功能失效