Skip to content

There are some XSS vulnerabilities in FeehiCMS-2.1.1 #69

Open
@Zzr7x

Description

There is a stored XSS vulnerability in the background of FeehiCMS.

First register a user for testing, then go to Content -> Single Page, upload any picture in the comment box.
image

Then send a comment, capture the odd packet while sending the Forward, change the value of SRC under the

tag in the packet to: 'x' [onerror='alert(1)', and send the message.
image

Refresh the page, and pop-up windows will appear on the current page and the home page.
image

image

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions