Skip to content
This repository has been archived by the owner on Dec 1, 2023. It is now read-only.
This repository has been archived by the owner on Dec 1, 2023. It is now read-only.

There is an XSS vulnerability in the place where the article is edited #968

Open
@BreakALegCml

Description

Problem

An attacker can insert a constructed statement into the article. When a user visits this page, it will trigger (XSS) cross site scripting attack

xss

EXP

<svg/onrandom=random onload=confirm(1)>
1
2

Technical Details

  • Pagekit version:1.0.18.
  • Webserver:apache2.4.39
  • Database:5.7.26
  • PHP Version:7.4.3

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions