Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cross Site Scripting(XSS) Vulnerability in Latest Release 4.3.7 Sub site new registration #1532

Closed
Aquilao opened this issue Aug 31, 2020 · 1 comment

Comments

@Aquilao
Copy link

Aquilao commented Aug 31, 2020

baserCMS 4.3.7 and earlier is affected by Cross Site Scripting (XSS).

Impact: XSS via Arbitrary script execution.
Attack vector is: Administrator must be logged in.
Tested baserCMS Version : 4.3.7(Latest)

payload:
"><svg/onload=alert(1)><--xsstest

image

image

image

@ryuring
Copy link
Collaborator

ryuring commented Sep 3, 2020

@Aquilao Hi. Thank you for reporting.

I am sending you an email. Did you see it?

I will close this issue.
I'm writing the reason in the email.

@ryuring ryuring closed this as completed Sep 3, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants