Skip to content
This repository has been archived by the owner on Mar 6, 2022. It is now read-only.

There have Storage type XSS vulnerability that can excute javascript #2

Closed
K1ns0 opened this issue Aug 20, 2018 · 2 comments
Closed

Comments

@K1ns0
Copy link

K1ns0 commented Aug 20, 2018

Here is a XSS vulnerability.
No login required.
Just need to open an article and comment on it.
For example,this article:
c61 37_fu3 sl6pal0b0

#######################################################################
Add comments here---->
image

#######################################################################
When I click Submit,it will pop up XSS---->
image

#######################################################################
Here is the page source code---->
image

And opening comments in the background will also pop up XSS.

@VictorAlagwu
Copy link
Owner

Thanks, for taking out time to run this program, this project was developed when I first started learning PHP, that is about two years ago, but you can send a pull request that contains a fix to this issue, would really appreciate
Thanks.

@K1ns0
Copy link
Author

K1ns0 commented Aug 21, 2018

I am also learning this knowledge. I can just practise, Lift a finger.
Thanks for your CMS :>)

@K1ns0 K1ns0 closed this as completed Aug 21, 2018
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants