Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.Sign up
MiniCMS reflective XSS in domain.com/mc-admin/post-edit.php #27
This is a reflective XSS vulnerability because "echo $_SERVER['REQUEST_URI'];" in post-edit.php 152 line
In Firefox and chrome, URL will be URLencoded.
After logging in, XSS is triggered using exp