jeecms v9.3 has a stroed xss vulnerability

An issue was discovered in jeecms v9.3 There is a stored XSS attacks vulnerability which allows remote attackers to inject arbitrary web script or HTML.

poc

<script>alert(document.cookie)</script>

Vulnerability trigger point
http://localhost//jeeadmin/jeecms/index.do#/content/update?type=update&id=130&noce_str=F3BR4K6
1.logged as admin
jeecms v9.3 has a stroed xss vulnerability
2.Choose this part
jeecms v9.3 has a stroed xss vulnerability
3.Click the green button to enter this page and insert code

jeecms v9.3 has a stroed xss vulnerability
4.Submit and view homepage
jeecms v9.3 has a stroed xss vulnerability

相关文章: