Closed
Description
Using mogu2021:mogu2021 to log in the Mogu blog.
http://demoweb.moguit.cn/


Choose User Center > User Avatar > Image


At this point, use the burp suite to capture the request packet.
Use the Repeater module in BurpSuite.
Try to change the file contents in the request package to the XSS payload and try to change the file name to the HTML suffix.
You can see the successful upload and the file path in the response package.

Open your browser to access the HTML file you just uploaded
