Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cross Site Scripting(XSS) Vulnerability in Latest Release 4.3.7 New category registration #1531

Closed
Aquilao opened this issue Aug 31, 2020 · 1 comment

Comments

@Aquilao
Copy link

Aquilao commented Aug 31, 2020

baserCMS 4.3.7 and earlier is affected by Cross Site Scripting (XSS).

Impact: XSS via Arbitrary script execution.
Attack vector is: Administrator must be logged in.
Tested baserCMS Version : 4.3.7(Latest)

payload:
"><svg/onload=alert(1)><--xsstest

image

image

image

@ryuring
Copy link
Collaborator

ryuring commented Sep 3, 2020

@Aquilao Hi. Thank you for reporting.

I am sending you an email. Did you see it?

I will close this issue.
I'm writing the reason in the email.

@ryuring ryuring closed this as completed Sep 3, 2020
baserproject pushed a commit that referenced this issue Oct 29, 2020
fix #1531 1532 1533 #1534 管理画面の文字列出力を改善
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants