Landing-CMS
Landing-CMS copied to clipboard
Landing-CMS has Storage Cross Site Scripting.
First access the file management page, then click new file to upload the file, select the html file format.
http://192.168.187.2/assets/vendor/responsive_filemanager_9.12.1/filemanager/dialog.php
payload:<script>alert(document.cookie)</scrtipt>
When we input the file content as payload, we find that the front end does not allow input /, so we can capture the package and modify the content or paste the payload directly into the file content.
data:image/s3,"s3://crabby-images/c1fc7/c1fc726a65fb0eb0bda5fff3215a7606ed440e35" alt="image"
Right-click the file and select "show url", open the file URL to trigger xss.
data:image/s3,"s3://crabby-images/b1467/b14673675205d847a9b1d2eb018349234883d392" alt="image"
data:image/s3,"s3://crabby-images/990ae/990aeaaa3140d649f68efecb927426c26ec0899f" alt="image"
data:image/s3,"s3://crabby-images/3959e/3959eb43a2fea91813b6c8505293926a4077805a" alt="image"
When the administrator opens the file after uploading the file, it can also trigger xss.
data:image/s3,"s3://crabby-images/f7197/f71972816cdf068f06f794d64519ff281046707d" alt="image"
data:image/s3,"s3://crabby-images/27b6b/27b6be51952c7954b3b0b3cb6ef45adc6c0cb981" alt="image"
data:image/s3,"s3://crabby-images/09f29/09f29dceedd43423ad85ca8c79aa17a3db9b15b2" alt="image"