Closed
Description
Reproduction process
1.Log in to the back office,Click on the background navigation function.

2.Click the Add Navigation button,Insert xss payload in the header,As shown below.

3.Then click save and go back to the front page of the cms to trigger the xss vulnerability.

Restoration suggestions
1.Backend filters input for pointed brackets.
2.Frontend uses html entity coding output.
Metadata
Assignees
Labels
No labels