cms
cms copied to clipboard
Cross Site Scripting On Image Upload Via File Name
Hi i found cross site scripting vulnerability on Feehi CMS via image upload.
POC:
- Go to https://demo.cms.feehi.com/admin/index.php?r=article%2Fupdate&id=postid
- Click on text editor and upload image with file name ">
.jpg
- You got alert
https://youtu.be/c3j-NZY65fQ