Skip to content

Cross-Site Scripting (XSS) in "/blogengine/api/posts" #254

Open
@tuando243

Description

A Cross Site Scripting vulnerabilty exists in BlogEngine via the Description field in /blogengine/api/posts

Step to exploit:

  1. Login as admin.
  2. Navigate to http://127.0.0.1/blogengine/admin/#/content/posts and click on "NEW".
  3. Insert XSS payload <img src=1 onerror=alert('XSS')> in the "Description" field and click on SAVE, PUBLISH.
  4. Go to Home page.

1

2

3

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions