Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
~ 1.9.1
~ stored xss
Visit the interface edit page, click edit, remarks, select markdown, insert payload in write mode: <svg onload=alert(document.domain)>
<svg onload=alert(document.domain)>
Click preview, successfully triggered, click OK to close the pop-up box, then click save, refresh the page, click edit, trigger storage xss
~ Firefox Chrome
Windows
The text was updated successfully, but these errors were encountered:
No branches or pull requests
版本号
~ 1.9.1
什么问题
~ stored xss
如何复现此问题
Visit the interface edit page, click edit, remarks, select markdown, insert payload in write mode:

<svg onload=alert(document.domain)>Click preview, successfully triggered, click OK to close the pop-up box, then click save, refresh the page, click edit, trigger storage xss

什么浏览器
~ Firefox Chrome
什么系统(Linux, Windows, macOS)
Windows
The text was updated successfully, but these errors were encountered: