IceCMS icon indicating copy to clipboard operation
IceCMS copied to clipboard

🌈冰激凌内容管理系统🍦,实现MacWK资源站,社区图片视频圈子CMS,支持网页端移动端小程序🌟适合做 资讯商城,社区论坛,聊天交友 社区,博客,圈子,论坛,图片,视频,社交。

Results 22 IceCMS issues
Sort by recently updated
recently updated
newest added

![录屏_选择区域_20230504110619](https://user-images.githubusercontent.com/26164116/236104405-ec9c4030-b984-4973-816d-a748b9c48aac.gif)

There is a Stored-XSS vulnerability in IceCMS v1.0.0 api : /Websquare/create/circle planet - circle POC: The payload is `` ![06](https://user-images.githubusercontent.com/35645904/235698897-baef4711-9678-4d5f-9453-38cfbe71d17f.png) ![05](https://user-images.githubusercontent.com/35645904/235699004-966ba0b0-8448-400c-b9d7-ec9bae10a60e.png)

![image](https://user-images.githubusercontent.com/26164116/234263527-6a4a60a9-0a0d-4311-8fa6-a9ffe06a4e43.png)

This api does not require login, obtains user information through user_id, and returns the user name, password, and email address in plain text. ![02](https://user-images.githubusercontent.com/35645904/235364459-98f11a8f-769d-48f9-8411-d6a117a22e2e.png) It is like the preview address...

Recently, our team discovered a security vulnerability that has led to an unauthorized access issue in the latest version of the project, which could pose a serious risk of information...

Recently, our team discovered a security vulnerability that has led to an unauthorized access issue in the latest version of the project, which could pose a serious risk of information...

Recently, our team discovered a security vulnerability that has led to an unauthorized access issue in the latest version of the project, which could pose a serious risk of information...

Recently, our team discovered a security vulnerability that has led to an unauthorized access issue in the latest version of the project, which could pose a serious risk of information...

Recently, our team discovered a security vulnerability that has led to an unauthorized access issue in the latest version of the project, which could pose a serious risk of information...

You can see in the figure below that the following API interface lacks authentication.(hithub is me) Iterate through the numbers in the figure below. By iterating through these numbers, you...