lsplugin-admin
lsplugin-admin copied to clipboard
XSS Vulnerability v2.0.1
Affected software : livestreet CMS
Version : v.2.0.1
Type of vulnerability : XSS (Cross-Site Scripting)
Author : Noth
Description: livestreet CMS is susceptible to cross-site scripting attacks, allowing malicious users to inject code into web pages, and other users will be affected when viewing web pages
Step 1 : login system
Step 2 : go to “/LiveStreet_2.0.1/admin/settings/config/main/” page
Step 3 : insert "XSS" test grammar in "Название сайта" and save it.
step 4 : Back to the front desk
This page available only for site admin
@lifecom Hi ~ Reply this Security issue to you, hope you can fix it . This is a Stored XSS !
Благодарю за помощь. Вы можете сделать вилку и работать с проектом как со своим
@olezhikz Thank you
@olezhikz Can I use this Security apply a CVE ID ?
https://cve.mitre.org/
Regards,
@olezhikz