eyoucms 1.4.6 XSS vulnerability


The project address: https://github.com/eyoucms/eyoucms

Vulnerability describes

Vulnerability found in Eyoucms1.4.6 and prior releases.
In the member center member contribution office, after editing the contribution content through the editor, intercept the data package, modify the parameter addonfieldext [content], and construct the payload “< img SRC=# οnerrοr=alert(document.cookie)>”eyoucms 1.4.6 XSS vulnerability
eyoucms 1.4.6 XSS vulnerability
After the administrator logs in the background, when viewing the content submitted by the user, it triggers the payload to obtain the cookie information.

eyoucms 1.4.6 XSS vulnerability

相关文章:

  • 2021-05-13
  • 2021-05-03
  • 2021-09-29
  • 2021-09-05
  • 2022-12-23
  • 2022-01-07
  • 2022-12-23
  • 2021-09-02
猜你喜欢
  • 2021-11-03
  • 2021-06-21
  • 2021-04-15
  • 2021-08-05
  • 2021-09-11
  • 2021-07-07
相关资源
相似解决方案