BlogEngine.NET
BlogEngine.NET copied to clipboard
Cross-Site Scripting (XSS) in "/blogengine/api/posts"
A Cross Site Scripting vulnerabilty exists in BlogEngine via the Description field in /blogengine/api/posts
Step to exploit:
- Login as admin.
- Navigate to http://127.0.0.1/blogengine/admin/#/content/posts and click on "NEW".
- Insert XSS payload
<img src=1 onerror=alert('XSS')>
in the "Description" field and click on SAVE, PUBLISH. - Go to Home page.